Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

configure pix 506e for multiple external interfaces

Posted on 2013-02-02
10
18 Views
Last Modified: 2016-05-20
Hello,
I have a time warner biz modem with 5 static ip addresses.
currently i have one outside ip defined, and static routes from this ip to various
places on the internal network - everything works fine.  I have installed a DVR/camera system, and want to use an additonal ip address from my static range provided by time warner.

ip address outside xxx.xxx.xxx.50 (current setting)
I would like to add xxx.xxx.xxx.51 and set a static route, nat, etc to 192.168.1.200, using
various ports like www, 5920, etc.  my global setting is : global (outside) 1 interface.

How can I do this???

Thanks,
eholz_one
0
Comment
Question by:eholz_one
  • 4
  • 3
10 Comments
 
LVL 57

Accepted Solution

by:
Pete Long earned 500 total points
ID: 38846977
Here you go....................

static (inside,outside) xxx.xxx.xxx.51 192.168.1.200 netmask 255.255.255.255
access-list inbound extended permit tcp any host xxx.xxx.xxx.51 eq 5920
access-list inbound extended permit tcp any host xxx.xxx.xxx.51 eq www
access-group inbound in interface outside

Note: This assumes you do NOT have an inbound ACL (Issue a show acess-group command to find out), if you do it will say access-group {name} in interface outside, Simply replace the word inbound above for the name of yours and DONT issue the command that starts access-group.
0
 
LVL 27

Expert Comment

by:davorin
ID: 38847011
If I understand correctly you are looking for 1to1 NAT.
Please look at this link:
http://serverfault.com/questions/382705/configuring-pix-506-with-nat-for-multiple-public-addresses
0
 

Author Comment

by:eholz_one
ID: 38847536
Thanks,!!!  I will give this a try! and respond as needed
0
Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

 

Author Comment

by:eholz_one
ID: 38847602
Hello Again,

No luck, pix fw version is 6.3 (4), and does not accept the "extended" word in the command line!

ouch,

eholz_one
0
 
LVL 27

Expert Comment

by:davorin
ID: 38847740
Have you tried without extended (format posted in link)?
access-list outside_access_in permit tcp any host <IP address> eq port
0
 

Author Comment

by:eholz_one
ID: 38848834
Yes, I have tried this.  It does not work, but it may not be the pix settings.
I will have to get with timewarner to verify we really have 4 more functional external ip addresses!!

thanks for the help
0
 
LVL 27

Expert Comment

by:davorin
ID: 38848901
You can verify that with configuring a laptop with that IP and connecting it to modem.
0
 

Author Comment

by:eholz_one
ID: 38848910
I did find the solultion - the external ips are working. reconfigure pix without the "extended" settings, and revised the static line to:
static (inside,outside) xxx.xxx.xxx.51 192.168.1.200
and added the appropriate ports to the access list.

thenks for info
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Meet the world's only “Transparent Cloud™” from Superb Internet Corporation. Now, you can experience firsthand a cloud platform that consistently outperforms Amazon Web Services (AWS), IBM’s Softlayer, and Microsoft’s Azure when it comes to CPU and …
For many of us, the  holiday season kindles the natural urge to give back to our friends, family members and communities. While it's easy for friends to notice the impact of such deeds, understanding the contributions of businesses and enterprises i…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

808 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question