I would create an access-list that specifies traffic from the DMZ to the LAN and then apply nat 0 to that acl. You will also need to create security rules to allow the DMZ to talk to a higher security level interface.
Chris.
**********************
Chris A.C, CCNA, CCSA
**********************
The op stated, "to allow the dmz to talk to the inside" so yes, to allow the DMZ to talk to the inside, security rules need to be created. The inside will be able to connect to the DMZ without any rules.
Chris.
**********************
Chris A.C, CCNA, CCSA
**********************
just take care to have a version higher than 6.xx. (I think 6.3.1 is ok) older one can not do "no nat" like that and you are obliged to work with static instruction.
Just one more point of interest. When you use "nat (inside) 0", you are not actually disabling NAT at all. The packet is NATed, just with the exact same address. The Pix will not pass any packets that do not have a translation slot as NAT is the basis for the operation of the Pix.
Chris
**********************
Chris A.C, CCNA, CCSA
**********************
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.