Building configuration...
: Saved
:
PIX Version 6.2(2)
nameif ethernet0 outside security0
nameif ethernet1 inside security100
fixup protocol http 80
fixup protocol smtp 25
no fixup protocol ftp 21
no fixup protocol h323 h225 1720
no fixup protocol h323 ras 1718-1719
no fixup protocol ils 389
no fixup protocol rsh 514
no fixup protocol rtsp 554
no fixup protocol sip 5060
no fixup protocol skinny 2000
no fixup protocol sqlnet 1521
names
object-group network Exch_In_Server
network-object 192.168.X.XXX 255.255.255.255
object-group network Exch_Out_Server
network-object 2YY.YYY.YYY.YYY 255.255.255.255
access-list inside_access_in permit udp object-group acl_permit_in any
access-list inside_access_in permit tcp object-group acl_permit_in any
access-list outside_access_in permit tcp host 2YY.YYY.YYY.YYY host XXX.XXX.XXX.XXX
pager lines 24
interface ethernet0 10baset
interface ethernet1 10full
mtu outside 1500
mtu inside 1500
ip address outside внешнийIP 255.255.255.252
ip address inside внутреннийIp 255.255.255.0
arp timeout 14400
global (outside) 2 interface
global (outside) 3 XXX.XXX.XXX.XXX
nat (inside) 2 192.168.X.0 255.255.255.0 0 0
static (inside,outside) XXX.XXX.XXX.XXX 192.168.X.XXX netmask 255.255.255.255 0 0
access-group outside_access_in in interface outside
access-group inside_access_in in interface inside
route outside 0.0.0.0 0.0.0.0 ZZZ.ZZZ.ZZZ.ZZZ 1
timeout xlate 0:05:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h323 0:05:00 sip 0:30:00 sip_media 0:02:00
timeout uauth 0:05:00 absolute
aaa-server TACACS+ protocol tacacs+
aaa-server RADIUS protocol radius
aaa-server LOCAL protocol local
no snmp-server location
no snmp-server contact
snmp-server community public
no snmp-server enable traps
: end
[OK]
вообщем такие вот пирожные.
транслируемый IPшник ХХХ.ХХХ.ХХХ.ХХХ принадлежит внеешней подсети.
если прописать вместо него IPвнешнего интервейса, то он (PIX) никого из внутренней, тогда во внешнюю сеть не пускает, кроме 192.168.Х.ХХХ хоста.