PIX DMZ Internet access

Posted on 2008-06-10
Last Modified: 2013-11-16
I have a Cisco PIX 515 with a dmz interface enabled. The pc I have put in the dmz can get to the internal network through an access list, but is unable to get to the internet. Below is my DMZ config.

access-list dmz extended permit ip any any

static (dmz,inside) netmask
static (inside,dmz) netmask
static (dmz,outside) netmask dns
static (dmz,outside) netmask dns
static (dmz,outside) netmask
static (dmz,outside) netmask
static (dmz,outside) netmask
access-group outside in interface outside
access-group dmz in interface dmz
Question by:dtadmin
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
LVL 28

Expert Comment

ID: 21754770
What do your "nat" and "global" statements look like?

Author Comment

ID: 21754845
global (outside) 1 interface
nat (inside) 0 access-list nonat-vpn
nat (inside) 1
LVL 15

Expert Comment

ID: 21755943
nat (dmz) 1 0 0
Free learning courses: Active Directory Deep Dive

Get a firm grasp on your IT environment when you learn Active Directory best practices with Veeam! Watch all, or choose any amount, of this three-part webinar series to improve your skills. From the basics to virtualization and backup, we got you covered.


Author Comment

ID: 21755975
what exactlly is nat (dmz) 1 0 0 telling me?
LVL 15

Expert Comment

ID: 21755987
It says that all access from DMZ when going "outbound" (less secure interface), should be NATed to the global pool on that interface with id 1.

In this case any traffic from DMZ that goes to Internet will be PATed into the PIX outside IP. (Same as is done for traffic from inside).
LVL 15

Expert Comment

ID: 21755991
Well, since you have statics it's not really true that it's ANY traffic.  Cuz the statics have precedense, and thus those will not use the dynamic NAT.

Accepted Solution

raptorjb007 earned 500 total points
ID: 21756244
Voltz-dl is correct.

Try adding

nat (dmz) 1

This command will configure your Pix to apply PAT or "NAT overload" to the DMZ VLAN, it is the counterpart to the "nat (inside) 1" command you already have configured for the inside vlan. Without a the nat command applied to the dmz vlan any device without a static translation will be unable to access the internet as it cannot be translated to an internet address.

Basically, with the "nat(dmz) 1 0 0" command applied, any device on your DMZ VLAN without a static translation will utilize the outside interface's IP address to access the internet.

Featured Post

Ready to trade in that old firewall?

Whether you need to trade-up to a shiny new Firebox or just ready to upgrade from whatever appliance you're using now, WatchGuard has the right appliance for you! Find your perfect Firebox today with appliance sizing tool!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
WARNING:   If you follow the instructions here, you will wipe out your VTP and VLAN configurations.  Make sure you have backed up your switch!!! I recently had some issues with a few low-end Cisco routers (RV325) and I opened a case with Cisco TA…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Suggested Courses

615 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question