Re: Overiding Nat statement in PIX



Hi Simon,

According to
http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/cmdref/s.htm#wp1026694,
it looks as if you will have to recreate the nat 0 statement to be a
bit more granular. It takes precedence over all other NAT statements,
so that is why your static NAT will not work in the current
configuration.

Can someone else confirm this?

Thanks,
Phillip

simon watson wrote:
Hi All

I've had a request to perform a port redirect from a NAT address on a PIX
(i.e a public address on the outside interface (i.e 86.1.1.1 tcp port 6000)
gets translated to an inside address and a recognisable port (i.e 10.1.1.1
port 23).

The NAT side already happens on the internet router, however to do the port
redirect bit, I will have to configure the PIX.

The problem is the previous administration had configured the pix not to
translate any addresses from the inside(the internet router translates all
inside addresses)

static (inside,outside) 10.1.0.0 10.1.0.0 netmask 255.255.0.0 0 0

nat (inside) 0 0.0.0.0 0.0.0.0 0 0



Therefore when I try to do the redirect, I get the error message that it
will overlap the statments above.



Is there any way I can perform the redirect, and keep the above statements
or do I have to modify the above static & nat statement to get it to work



Many Thanks in advance



Simon

.



Relevant Pages

  • SuSE 9.1: iptables problem (-t nat OUTPUT) - a bug???
    ... the address translation in the OUTPUT nat table is not ... redirect an access to the external destination port 80 to port 3128 ... In the firewall script above I have installed a redirect in the ... PREROUTING chain and I have locked the INPUT chain in order to be able ...
    (comp.os.linux.networking)
  • Re: ISPs can easily decrease net abuse
    ... |use NAT with forwarding? ... When one of the inside systems wants to go out, the NAT device has to ... address to as it sends out the packets. ... Suppose the NAT box allocates port ...
    (comp.security.misc)
  • Re: port redirection with pf
    ... > Having problems trying to redirect traffic here.. ... Interface fxp0: This is connected to a network switch ... > other PC's can use the machines NAT for internet access.. ... the port is still closed (firewall set to default ...
    (comp.unix.bsd.openbsd.misc)
  • Re: How did they get past my NAT?
    ... network), I get no response, because there is no "Default host" set up ... behind my NAT, and no port forwarding for that port - if an explicit ... as I understand?), and not forwarded on the router, so there should be ...
    (comp.security.firewalls)
  • Re: Processs PreciseMail AntiSpam Gateway - any experience so far ?
    ... Client sending system ... >> ISP using dynamic NAT with port overloading. ... >> 10.11.12.1 is the clients real address and it opens a connection from its port ...
    (comp.os.vms)