Muliple networks behind PIX
Posted on 2007-12-04
I have a PIX 515e running 8.0(2), ASDM 6.0(2).
My provider has a private network between my router and their network. This is a tiny subnet which is assigned to Ethernet0/0 (outside), lets call this providerSubnetA.
My provider has also given me two other networks to use. Lets call them publicSubnetA and publicSubnetB.
I also have a private network, a 172.x.x.x network - lets call this privateSubnetA.
Until now, I've natted IPs in publicSubnetA to privateSubnetA. Ethernet0/1 (inside) has an IP on privateSubnetA, which is the default GW for all machines on privateSubnetA. This works great.
What I now need to do is give a few machines public IPs directly on publicSubnetB.
What I believe I need to do is add an IP on publicSubnetB.to my PIX, and add a nat rule for each IP on publicSubnetB from outside to inside, same IP on both ends of the NAT, as well as set up firewall rules to allow incoming and outgoing traffic. My problem at this point is silly... I can't figure out how to add an IP on publicSubnetB to my PIX. I tried adding on to Ethernet0/1.1, but it makes me put it on a vlan. I don't know if this will work... I can't do vlan tagging on my machine... and I don't know if I need to or not, but when I do it I know I can't ping from a machine on publicSubnetB to the IP on publicSubnetB that I added on Ethernet0/1.1.