Cisco PIX 525 Especificaciones Pagina 98

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 466
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 97
2-38
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 2 Establishing Connectivity
Using Outside NAT
Replace old_vlan_id with the existing VLAN ID and replace new_vlan_id with the new VLAN ID you
want to use.
This command lets you change the VLAN ID without removing the logical interface, which is helpful if
you have added a number of access-lists or firewall rules to the interface and you do not want to start
over.
To disable VLAN tagging on the interface, enter the following command:
no interface ethernet0 vlan_id physical
Replace vlan_id with the VLAN ID for which you want to disable VLAN tagging.
To remove the logical interface and remove all configuration, enter the following command:
no interface ethernet0 vlan_id logical
Replace vlan_id with the VLAN ID associated with the logical interface that you want to remove.
Caution Using this command removes the interfaces and deletes all configuration rules applied to the interface.
Using Outside NAT
Starting with PIX Firewall Version 6.2, NAT and PAT can be applied to traffic from an outside or less
secure interface to an inside (more secure) interface. This functionality is called outside NAT and
provides the following benefits:
Provides transparent support for Domain Name System (DNS)
Simplifies routing by specifying the IP addresses that appear on the more secure interfaces of the
PIX
Firewall
Enables connectivity between networks with overlapping IP addresses
For information about how outside NAT enhances support for DNS, refer to the “Basic Internet
Protocols” section in Chapter 5, “Configuring Application Inspection (Fixup).
Note Outside NAT does not work with application inspection (“fixup”) for Internet Locator Service (ILS).
This section describes the last two scenarios and includes the following topics:
Overview, page 2-38
Simplifying Routing, page 2-39
Configuring Overlapping Networks, page 2-40
Overview
Outside NAT/PAT is similar to inside NAT/PAT, only the address translation is applied to addresses of
hosts residing on the outer (less secure) interfaces of the PIX
Firewall. To configure dynamic outside
NAT, specify the addresses to be translated on the less secure interface and specify the global address or
addresses on the inside (more secure) interface. To configure static outside NAT, use the static command
to specify the one-to-one mapping.
Vista de pagina 97
1 2 ... 93 94 95 96 97 98 99 100 101 102 103 ... 465 466

Comentarios a estos manuales

Sin comentarios