Solved

multiple public ip address cisco pix

Posted on 2010-11-29
4
803 Views
Last Modified: 2012-05-10
How to enter multiple public ip addresses in cisco pix firewall?
0
Comment
Question by:Hersh
  • 2
4 Comments
 
LVL 79

Expert Comment

by:lrmoore
Comment Utility
Only way to do that is to create multiple static NAT statements using multiple public IP addresses.

Example:

outside interface IP 12.34.5.2 255.255.255.248

static (inside,outside) 12.34.5.3 192.168.100.103 netmask 255.255.255.255
static (inside,outside) 12.34.5.4 192.168.100.104 netmask 255.255.255.255
<etc>

Your static nat's can be from a different IP subnet than the interface only if the ISP routes a different subnet directly to your interface IP.
0
 
LVL 17

Assisted Solution

by:StrifeJester
StrifeJester earned 100 total points
Comment Utility
You can also use a pool if you want multiple user for outbound or for certain groups of IPs to get certain external IPs while on the internet
0
 

Author Comment

by:Hersh
Comment Utility
I created port forwarding rule in cisco pix for RDP access to my server. I want only specific ip should access my server using RDP how can I edit such rule ?
0
 
LVL 79

Accepted Solution

by:
lrmoore earned 400 total points
Comment Utility
Do that with the access-list

access-list outside_access_in permit tcp host 1.2.3.4 interface outside eq 3389
access-list outside_access_in permit tcp host 2.3.4.5 interface outside eq 3389
no access-list outside_access_in permit tcp any interfact outside eq 3389

I'm assuming that you created a simple port forward something like this:
static (inside,outside) tcp interface 3389 192.168.1.100 3389 netmask 255.255.255.255
0

Featured Post

Why You Should Analyze Threat Actor TTPs

After years of analyzing threat actor behavior, it’s become clear that at any given time there are specific tactics, techniques, and procedures (TTPs) that are particularly prevalent. By analyzing and understanding these TTPs, you can dramatically enhance your security program.

Join & Write a Comment

Suggested Solutions

This article assumes you have at least one Cisco ASA or PIX configured with working internet and a non-dynamic, public, address on the outside interface. If you need instructions on how to enable your device for internet, or basic configuration info…
Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…
Polish reports in Access so they look terrific. Take yourself to another level. Equations, Back Color, Alternate Back Color. Write easy VBA Code. Tighten space to use less pages. Launch report from a menu, considering criteria only when it is filled…

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now