"secondary" PIX NAT/PAT pools



All the configuration examples I've been able to find for PIXes show NAT
and PAT address pools being taken from the address range on the outside
interface of the PIX. Is there any way to map inside addresses to a
separate pool of addresses which could be routed to the PIX?

Background: we have an FWSM running PIX OS 3.1(x) and until recently we
were exclusively using identity NAT (no translation) with a /29 on the
outside interface. We now need to start doing NAT for a significant
number of addresses. We have enough public addresses available to
provide a large pool of outside addresses, say a /23, but I can't see a
way to use them without readdressing the outside network and a
corresponding break in service while I do it.

Any ideas?

Sam
.



Relevant Pages

  • Re: problem with setting nat using pf
    ... Only natted addresses should be accessible via interface, ... addresses in pool which still no session is natted to them. ... I am trying to use pf nat rules with pool support on FreeBsd 8.0, ... in this configs the dafult route of system A and system B are the middle ...
    (freebsd-net)
  • Re: Order significance for PIX nat / global statements?
    ... >> Studying PIX firewall configuration I'm confused by some contradictions ... > addition to the two nat statements shown above. ... >> PAT address pool? ... > The PIX will NAT first, then PAT. ...
    (comp.security.firewalls)
  • Re: Inbound connections on a 515e without NAT
    ... I have a PIX 5i5E configured that permits outbound connections ... is we aren't doing NAT, and are using the same addresses inside as ... global 1 interface ... access-group permit_web in interface outside ...
    (comp.dcom.sys.cisco)
  • Re: NAT-T + VPN Tunnel
    ... >And the router on the outside has a static translation for the PIX ... >interface and a destination network somewhere on the Internet, ... Your NAT is probably ... assuming overloading and changing the port to one Cisco does not ...
    (comp.dcom.sys.cisco)
  • Pix Outside NAT
    ... I have a pix that connects to 2 internet links. ... I have been thinking of puting the 2nd link on a separate interface on ... direction) so that when my inside host replies it will reply to the NAT ...
    (comp.dcom.sys.cisco)