We have a pix 515E with a web- and mail server in the DMZ.
For our inside users we want to use the external host name for retriving mail, so i inserted the alias command which works perfectly so far i know..
But when running the PDM it says the alias cmd is not longer supported and that it should be replaced with Outside Nat / Bi-directional-NAT
i have tried adding dns to the static cmd, but that doesnt work.
What to do now?
fixup protocol dns maximum-length 512
name 10.1.1.10 Webserver
access-list acl_out permit tcp any host 195.xxx.xxx.195 eq www
access-list DMZ_outbound_nat0_acl permit ip 10.1.1.0 255.255.255.0 192.168.1.0 255.255.255.0
global (outside) 10 195.xxx.xxx.196
global (DMZ) 10 195.xxx.xxx.195
nat (inside) 0 access-list inside_outbound_nat0_acl
nat (inside) 10 192.168.0.0 255.255.255.0 0 0
nat (DMZ) 10 10.1.1.0 255.255.255.0 0 0
alias (inside) 195.xxx.xxx.195 10.1.1.10 255.255.255.255
static (DMZ,outside) 195.xxx.xxx.195 10.1.1.10 dns netmask 255.255.255.255 0 0
access-group acl_out in interface outside
sysopt noproxyarp inside
As i look now, i don't see any nat 0 for the DMZ.. maybe my solution lies here..