Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Cisco > Pix 515E: static (High,Low) .... with SAME(!) IP's?

Reply
Thread Tools

Pix 515E: static (High,Low) .... with SAME(!) IP's?

 
 
Rainer Blaes
Guest
Posts: n/a
 
      10-15-2004
Dear all,

as a newbie I'm learning step by step howto configure
our Pix 515E for several configurations.
During this process I saw somewhere in any manual this
command:

static (inside,dmz) 111.112.113.114 111.112.113.114 netmask 255.255.255.255 0 0

At the moment I can't find out what's the reason for this 1:1
mapping especially the dmz interface has the IP 133.134.135.136.
IMHO there is no chance that the "mapped" 111.112.113.114 is able to
communicate with any host in the dmz since there is no router in this zone.
Many thanks for bringing some light into my confusion about the command above!

Rainer
 
Reply With Quote
 
 
 
 
dw
Guest
Posts: n/a
 
      10-15-2004
Rainer Blaes wrote:

> During this process I saw somewhere in any manual this
> command:
>
> static (inside,dmz) 111.112.113.114 111.112.113.114 netmask 255.255.255.255 0 0
>
> At the moment I can't find out what's the reason for this 1:1
> mapping especially the dmz interface has the IP 133.134.135.136.


Basically this says that when address 111.112.113.114 on the "inside"
interface talks to a host in the "dmz" interface segment, the host on
the dmz will see the source IP of 111.112.113.114, basically unchanged.

-DW
 
Reply With Quote
 
 
 
 
PES
Guest
Posts: n/a
 
      10-16-2004

"dw" <> wrote in message news:bzPbd.4508$EZ.980@okepread07...
> Rainer Blaes wrote:
>
>> During this process I saw somewhere in any manual this
>> command:
>>
>> static (inside,dmz) 111.112.113.114 111.112.113.114 netmask
>> 255.255.255.255 0 0
>>
>> At the moment I can't find out what's the reason for this 1:1
>> mapping especially the dmz interface has the IP 133.134.135.136.

>
> Basically this says that when address 111.112.113.114 on the "inside"
> interface talks to a host in the "dmz" interface segment, the host on the
> dmz will see the source IP of 111.112.113.114, basically unchanged.
>
> -DW


True, but the same would hold true for nat 0. This configuration would be
for the dmz host talking to the inside host of 111.112.113.114 using its
(the inside hosts) native address.


 
Reply With Quote
 
Rainer Blaes
Guest
Posts: n/a
 
      10-18-2004
"PES" <NO*SPAMpestewartREMOVE**SUCK S> wrote in message news:<417170c0$>...
> "dw" <> wrote in message news:bzPbd.4508$EZ.980@okepread07...
> > Rainer Blaes wrote:
> >
> >> During this process I saw somewhere in any manual this
> >> command:
> >>
> >> static (inside,dmz) 111.112.113.114 111.112.113.114 netmask
> >> 255.255.255.255 0 0
> >>
> >> At the moment I can't find out what's the reason for this 1:1
> >> mapping especially the dmz interface has the IP 133.134.135.136.

> >
> > Basically this says that when address 111.112.113.114 on the "inside"
> > interface talks to a host in the "dmz" interface segment, the host on the
> > dmz will see the source IP of 111.112.113.114, basically unchanged.
> >
> > -DW

>
> True, but the same would hold true for nat 0. This configuration would be
> for the dmz host talking to the inside host of 111.112.113.114 using its
> (the inside hosts) native address.



Fine but is there no need for a router in the dmz in the case 111.112.113.114
wants to talk to a dmz host with 133.134.135.137?
How or from where does the PIX know the route from the 111.112.113-Lan into the
Lan 133.134.135.0?

Rainer
 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
PIX - Static mappings to hosts on remote subnets behind PIX btercha@omegasystemscorp.com Cisco 2 08-22-2006 02:27 AM
pix to pix dhcp to static vpn jspr Cisco 5 07-29-2005 09:01 PM
PIX public/24 ip static mapping means 256 times interfaces static maps? Nieuws Xs4all Cisco 2 05-26-2005 06:25 PM
PIX public/24 ip static mapping means 256 times interfaces static maps? Nieuws Xs4all Cisco 0 05-26-2005 11:07 AM
PIX NIX : A simple static and access-list (below) seems to have prevented ANY access through the PIX to the web. J Bard Cisco 2 01-10-2004 06:44 PM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57