
Field Descriptions
The Create host/network>NAT (Network Address Translation) dialog box displays a set of rows, one for each
higher security interface, containing the following fields:
Static—Selecting this option defines a permanent map between the internal IP address and a valid IP
address on the lower security interface. This rule allows hosts from the lower security interface to gain
access to the selected host or network, and vice versa. When this option is selected, the Static box and the
Advanced button appear.
<address_value>—Identifies the IP address (translated address) that is exposed to the interface from
which the network or host's address is hidden. The PIX Firewall uses this address to replace the
network or host's address for any network packets that traverse from the interface on which the
network or host exists to the interfaces listed in the rule. This value is the specific translated IP
address to which you want to map the original addresses of the translated object. You can define
exactly one address.
❍
Advanced—Clicking this button opens the
Static NAT Options
dialog box, from which you can
configure the maximum connections permitted through this static address, the maximum number of
embryonic connections allowed, and whether the PIX Firewall unit generates random sequence
numbers for TCP packets belonging to a translated session.
❍
●
Dynamic—Selecting this option defines a dynamic NAT rule. The rule dictates which address pool is used
to translate addresses for the host or network being added when the host initiates a connection passing
through the interface. When this option is selected, the Addresses Pool ID list and the Manage Pools
buttons appear.
Address Pool ID—Identifies the type of dynamic NAT rule to define for the selected host or
network. You can select one of the following values in this list:
No NAT—Specifies that no dynamic NAT rule be used for the selected host or network. If an
existing dynamic NAT rule covers the selected address (such as one for the network to which
a host address belongs) or the selected interfaces is the outside interface, this option does not
appear. If there is an existing rule, you can edit that rule on the Translation Rules tab.
■
same address— Specifies that the PIX Firewall unit use the original IP address of the selected
host or network to access hosts on the interface specified in the dynamic rule. This type of rule
is different from a static rule because the address is not exposed to the lower security interface.
■
<ID_number>—Specifies that the PIX Firewall unit use the address(es) define by this address
pool for the selected network or host. For PAT-based rules, this address can be a valid IP
address or the address that is assigned to the external interface. This list of pools only includes
the predefined pools on lower security interfaces.
■
❍
Manage Pools—Clicking this button opens the
Manage Global Address Pools
dialog box, from
which you can view, add to, or delete from the existing address pool definitions.
❍
●
Back—Returns to the Create host/network>Static Route dialog box.
●
Finish—Creates the host or network and returns to the Hosts/Networks tab.
●
Cancel—Clears any changes you may have made and returns to the Hosts/Networks tab.
●
Help—Provides more information.
●
Summary of Contents for PIX 520 - PIX Firewall 520
Page 45: ...Copyright 2001 Cisco Systems Inc ...
Page 68: ...Copyright 2001 Cisco Systems Inc ...
Page 74: ...Copyright 2001 Cisco Systems Inc ...
Page 87: ...Copyright 2001 Cisco Systems Inc ...
Page 92: ...Copyright 2001 Cisco Systems Inc ...
Page 108: ......
Page 184: ......
Page 197: ...Copyright 2001 Cisco Systems Inc ...
Page 200: ......
Page 232: ...Copyright 2001 Cisco Systems Inc ...
Page 246: ...Copyright 2001 Cisco Systems Inc ...