In article < >,
Jeff <> wrote:
:I'm trying to access a static on the outside interface of our Pix,
:from the inside interface. Basically we run NAT on the inside with

rivate IP, and I have a public global list on the outside. I also
:have a static IP pointed to a 3rd DMZ interface for web services. I
:need to be able to access that static from the inside interface and my
:config is not letting me.
:Is this possible?
No, but you probably don't care. Just configure up a static between
the inside and DMZ interface using "outside nat".
e.g., if you need to reach dmz internal IP 192.168.45.69 via
the IP 2.1.1.158, then
static (dmz, inside) 2.1.1.158 192.168.45.69 netmask 255.255.255.255
Notice that the order of the interfaces is reversed relative to
a normal static, which normally has (high-security, low-security).
When the order is reversed, you have outgoing static processing.
Now, if you need to be able to access the DMZ host under *both*
IP addresses, 192.168.45.69 and 2.1.1.158, then you are in for problems.
Do you really need to access the DMZ host by its outside IP?
Or would it be good enough to be able to access it by its host *name*?
If your requirements are to access by *name*, then the PIX can
do DNS manipulation for you provided the DNS request crosses the PIX.
(If your DNS server is on your inside, then configure your DNS
server to return different information if queried by the inside
than the outside gets.)
--
Aleph sub {Aleph sub null} little, Aleph sub {Aleph sub one} little,
Aleph sub {Aleph sub two} little infinities...