Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations TouchToneTommy on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Advice on moving from NAT to PAT 1

Status
Not open for further replies.

zephyran

Technical User
Nov 30, 2001
311
US
We will be losing our existing IP addresses (a few hundred) and getting back 32 (long story). We have a PIX firewall as our connection to the Internet, and are currently using NAT for our clients (about 70).

We're therefore planning on moving to PAT. We don't have any critical software that requires specific ports for communication. Are there any problems we should expect when shifting from NAT to PAT? For instance, will Windows Media Player streaming audio/video no longer work? Thanks all!
 
HI.

You can expect problems with the following:

IPSec VPN tunnels established from the clients - these don't work behind PAT. No problem establishing a tunnel endpoint at the pix itself, or with STATIC mapping to a server behind the pix.

Some multimedia applications may have problems - I have never tested but keep asking around and make a pilot test if its important to you.

You can configure the pix to use PAT for a specific subnet and keep using NAT for the other, and make this way a pilot test before changing for everyone.

You can also use about 25 (the rest used by router, pix and static mappings) addresses for NAT after the change and only use PAT when this overflows. 70 clients will use the NAT most of the time.
See pix manuals at for details.

Bye

Yizhar Hurwitz
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top