stimpyman77

Member
Feb 18, 2004
120
0
71
Hi all,

Was doing some tinkering on the PIX 501 Software Version 6.3(5) and I can't seem to find the correct verbage for specifing a static map when the WAN uses DHCP. How is it configured so that it will use whatever IP is assigned? Can someone point me in the right direction? If I understand it right, you need to statically map the outside interface to the inside ip of the machine that will be receiving the connection. Is this not the case?

Say for example trying to forward port 31099 to an internal machine of 192.168.0.5

I was looking at this as a reference. How would that scenario work in the case where I am using PAT / overload.

Thanks!
 

stimpyman77

Member
Feb 18, 2004
120
0
71
Nightowl :beer: for you! Thank you very much. That clears it up completely. Nice linkage, it has been added to the bookmarks...

Thanks again!

I did not want to make another thread I will just edit here...

I understand what they are saying in the link you provided Nightowl, but I am still a little stuck. I can get the FTP access working but by mapping the outside interface to my FTP server on the inside, I end up killing the PAT that is happening for the rest of the network it almost seems like I need to be using 2 public ip's to accomplish this.


I want to be able to nat my 192.168.0.0 network while still being able to specify static mappings to provide services from hosts on the inside network. It also seems that I have to specify the wan IP on lines 4-5 to get it to work but if the DHCP WAN address changes these lists will have to be manually changed and that should not be, IMHO.

My access lists are as follows

access-list 100; 5 elements
access-list 100 line 1 permit icmp any any echo-reply (hitcnt=98)
access-list 100 line 2 permit icmp any any time-exceeded (hitcnt=57)
access-list 100 line 3 permit icmp any any unreachable (hitcnt=12)
access-list 100 line 4 permit tcp any host **WANIP** eq 55000 (hitcnt=27)
access-list 100 line 5 permit tcp any host **WANIP** range 63090 63100 (hitc
nt=5)

Nat / global statements are as follows

nat (inside) 1 0.0.0.0 0.0.0.0 0 0
global (internet) 1 interface

access-group 100 in interface internet

If more information is needed let me know.. I know that I am probably making this harder than it is and overthinking it.. if anyone can help me pull my head out of my ass on this it will be you guys!!

Thanks... (Bashing head on desk)

Stimpyman
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |