I have a PIX 506 with two interfaces. The PIX is only used between to
private network segements for some political reason. Here the description
is: PIX outside interface is on 198.199.199.0 network and PIX outside
interace address is 198.199.199.1 connected to Cataylyst switch. PIX Inside
interface is on 172.16.17.0 network and the Inside interace adddress is
172.16.17.2 is connected to another catalyst switch. The internal router is
also connected to catalyst switch and the ip address of the router is
172.16.17.1. I have configured the access-list to allow outside hosts to
access traffic on inside network. In order for traffic to go through between
the PIX and internal router, I asked customer to build a static route on a
router such as Ip route 198.199.199.0 255.255.255.0 172.16.17.2, but instead
they want to do NAT to translate outside address to the inside address. For
some political reason, they can't build the route into a router. Is address
translation possible between to private segments. I don't think it is
possible, and my reason are: If I use any fake segment such as 192.168.1.0,
just for translate customer's outside network to inside address, then I will
have to put my PIX's outside address on this fake segement. Outside hosts
default gateway will still be pointing at 198.199.199.1 address, and since
there is no router between the PIX's outside network and catalyst switch,
then the traffic from the hosts will not be able to reach to the PIX. Is
there any other solutions to provide connectivity between PIX outside
network and the Internal router without being installing a route into a
Internal router.

_______________________________________________
Join Excite! - http://www.excite.com
The most personalized portal on the Web!




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=64634&t=64634
--------------------------------------------------
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]

Reply via email to