Solved

configure pix 506e for multiple external interfaces

Posted on 2013-02-02
10
15 Views
Last Modified: 2016-05-20
Hello,
I have a time warner biz modem with 5 static ip addresses.
currently i have one outside ip defined, and static routes from this ip to various
places on the internal network - everything works fine.  I have installed a DVR/camera system, and want to use an additonal ip address from my static range provided by time warner.

ip address outside xxx.xxx.xxx.50 (current setting)
I would like to add xxx.xxx.xxx.51 and set a static route, nat, etc to 192.168.1.200, using
various ports like www, 5920, etc.  my global setting is : global (outside) 1 interface.

How can I do this???

Thanks,
eholz_one
0
Comment
Question by:eholz_one
  • 4
  • 3
10 Comments
 
LVL 57

Accepted Solution

by:
Pete Long earned 500 total points
ID: 38846977
Here you go....................

static (inside,outside) xxx.xxx.xxx.51 192.168.1.200 netmask 255.255.255.255
access-list inbound extended permit tcp any host xxx.xxx.xxx.51 eq 5920
access-list inbound extended permit tcp any host xxx.xxx.xxx.51 eq www
access-group inbound in interface outside

Note: This assumes you do NOT have an inbound ACL (Issue a show acess-group command to find out), if you do it will say access-group {name} in interface outside, Simply replace the word inbound above for the name of yours and DONT issue the command that starts access-group.
0
 
LVL 27

Expert Comment

by:davorin
ID: 38847011
If I understand correctly you are looking for 1to1 NAT.
Please look at this link:
http://serverfault.com/questions/382705/configuring-pix-506-with-nat-for-multiple-public-addresses
0
 

Author Comment

by:eholz_one
ID: 38847536
Thanks,!!!  I will give this a try! and respond as needed
0
 

Author Comment

by:eholz_one
ID: 38847602
Hello Again,

No luck, pix fw version is 6.3 (4), and does not accept the "extended" word in the command line!

ouch,

eholz_one
0
Give your grad a cloud of their own!

With up to 8TB of storage, give your favorite graduate their own personal cloud to centralize all their photos, videos and music in one safe place. They can save, sync and share all their stuff, and automatic photo backup helps free up space on their smartphone and tablet.

 
LVL 27

Expert Comment

by:davorin
ID: 38847740
Have you tried without extended (format posted in link)?
access-list outside_access_in permit tcp any host <IP address> eq port
0
 

Author Comment

by:eholz_one
ID: 38848834
Yes, I have tried this.  It does not work, but it may not be the pix settings.
I will have to get with timewarner to verify we really have 4 more functional external ip addresses!!

thanks for the help
0
 
LVL 27

Expert Comment

by:davorin
ID: 38848901
You can verify that with configuring a laptop with that IP and connecting it to modem.
0
 

Author Comment

by:eholz_one
ID: 38848910
I did find the solultion - the external ips are working. reconfigure pix without the "extended" settings, and revised the static line to:
static (inside,outside) xxx.xxx.xxx.51 192.168.1.200
and added the appropriate ports to the access list.

thenks for info
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

What is IRC? IRC (Internet Relay Chat) is a form of communication between multiple users. It is available freely to anyone with inernet access. IRC is a great way to communicate with others e.g. There is an IRC channel for Ubuntu Linux, which is fo…
If you're not part of the solution, you're part of the problem.   Tips on how to secure IoT devices, even the dumbest ones, so they can't be used as part of a DDoS botnet.  Use PRTG Network Monitor as one of the building blocks, to detect unusual…
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now