?
Solved

Pix - Change Static IP

Posted on 2011-02-23
11
Medium Priority
?
502 Views
Last Modified: 2012-05-11
Hi I am a newbie to Pix, and in fact just getting used to MS TMG 2010, which is going to replace a PIX 515E.
I am about to submit a new question to Experts Exchange about NLB on TMG2010, but since time is precious, we have decided to keep the PIX just now in the new infrastructure, though would like to remove it in the next week.

Basically, I can get to the config on the PIX, but I dont know the commands to do the following.
I have attached the current config.

We have an exchange server 192.168.2.15 and OWA on 192.168.2.17, this is Exchange 2003, as you can see in the config its NAT'ed to external addresses ending xxx.xxx.253.180 and xxx.xx.253.181
We are putting in a new Exchange 2010 server.
Right now its ip is 192.168.3.21, ie on a new subnet.

We want to test it works, ie accepts outside connections and routes to new Exchange, but since we need to keep current Exchange, we would like to change the NAT ending zzz.xxx.253.178, which was originally intended for Sharepoint, as I say for test purposes.

The client has 5 exernal IP's

So what do I need to do to change xxx.xx.253.178 192.168.2.16 to now go to xxx.xx.253.178 192.168.3.21 ?

As I say this is on a new subnet 3.x, I thought it may just be a case of changing that line but I see other lines in there and route inside only seems to go to 2.x (we recently added new vlans and subnets for the new infrastructure)

All passwords and external addresses are removed from the config attached for security.

Hope someone can help :-) I am not familiar with commands.

If this works, we intend to then point the addresses to the new machines over the next few days, ie sharepoint to 178, exchange to 180, etc.

Its a new domain as well for the new excahnge, we can change the DNS, etc to map the new domain to the external address okay.

ie companyold.com goes to 178 just now, we can change this to companynew going to 178 for the test.

Later we will remove the PIX all together

Bruce



pix.txt
0
Comment
Question by:Croftkey
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 4
11 Comments
 
LVL 9

Expert Comment

by:meko72
ID: 34965405
0
 

Author Comment

by:Croftkey
ID: 34965526
Thanks but I just need what I hope are a few lines of config to move the nat for 178 to the new exchange server for testing, i am new to this and I fear messing it up

Ideally I can change those lines but have the config saved first if I need to roll back

I see other lines which I assume are ports, I wonder if I need to assign ports as well for 178 as it was not originally intended for exchange (currently sharepoint)

We do plan to add sharepoint again but for now we want to use the static 178 address for testing exchange
0
 
LVL 12

Expert Comment

by:Fidelius
ID: 34965982
Hello,

Can you post sanitized config (remove passwords, and at least first two octets of all public IP's) and I will write you down exact commands you need to enter to modify your config.

Regards!
0
Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 

Author Comment

by:Croftkey
ID: 34967487
Hi thanks I attached this in first post
0
 
LVL 12

Expert Comment

by:Fidelius
ID: 34968478
Hello,

First you need to allow access from outside:
access-list outside_access_in permit tcp any host xxx.xx.253.178 eq https
access-list outside_access_in permit tcp any host xxx.xx.253.178 eq 993
access-list outside_access_in permit tcp any host xxx.xx.253.178 eq 587
access-list outside_access_in permit tcp any host xxx.xx.253.178 eq 82

Then you need to change static NAT rule:
no static (inside,outside) xxx.xx.253.178 192.168.2.16 netmask 255.255.255.255 0 0
static (inside,outside) xxx.xx.253.178 192.168.3.21 netmask 255.255.255.255 0 0


As you have this route already, routing should not be the problem.
route inside 192.168.0.0 255.255.0.0 192.168.2.254 1


Regards!
0
 
LVL 12

Accepted Solution

by:
Fidelius earned 2000 total points
ID: 34968488
I forgot to apologize about my config request.
I overlooked that info in original post. My mistake.

Sorry!
0
 

Assisted Solution

by:Croftkey
Croftkey earned 0 total points
ID: 34968581
No thats okay, thanks for your help
Based upon what you have sent, I would also need smtp as its mail so I have added these lines

Would I also need to run a command to commit these changes? Xlate or something like that?

access-list outside_access_in permit tcp any host xx.xx.178 eq https
access-list outside_access_in permit tcp any host xx.xx.253.178 eq 993
access-list outside_access_in permit tcp any host xx.xx.253.178 eq 587
access-list outside_access_in permit tcp any host xx.xx.253.178 eq 82
access-list outside_access_in permit tcp host 77.68.61.117 host xx.xx.253.178 eq smtp
access-list outside_access_in permit tcp host 77.68.61.118 host xx.xx.253.178 eq smtp
no static (inside,outside) xx.xx.253.178 192.168.2.16 netmask 255.255.255.255 0 0
static (inside,outside) xx.xx.253.178 192.168.3.21 netmask 255.255.255.255 0 0
0
 
LVL 12

Expert Comment

by:Fidelius
ID: 34968898
Lines for SMTP look OK.

Changes are applied as soon as you enter them. You just need to write config, to store it.
PIX# write memory

You can also issue
PIX# clear xlate
to clear all NAT translations from memory. It will disrupt all traffic for a moment, as all active NAT translations will be removed and then created again. Maybe, you will need to execute it few times in a row, for it to take effect (known issue).



 
0
 

Author Comment

by:Croftkey
ID: 34970883
Hi seems to have worked, many thanks.
If I accept that as solution will it assign points to you Fidelius?
I have had experts exchange for a year or so, but only recently started to use, I need to close a few tickets.

Thanks again
0
 

Author Comment

by:Croftkey
ID: 34970917
Closing off as solved
0
 

Author Closing Comment

by:Croftkey
ID: 35005135
Resolved issue as required
0

Featured Post

On Demand Webinar - Networking for the Cloud Era

This webinar discusses:
-Common barriers companies experience when moving to the cloud
-How SD-WAN changes the way we look at networks
-Best practices customers should employ moving forward with cloud migration
-What happens behind the scenes of SteelConnect’s one-click button

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
Arrow Electronics was searching for a KVM  (Keyboard/Video/Mouse) switch that could display on one single monitor the current status of all units being tested on the rack.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses

765 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question