In article , Mr Corbett wrote: :At the moment I have the 515 using 1 External IP and natting, then I use :the switch.
I am not clear whether the switch is "inside" or "outside" the PIX?
:Is it possible to use 1 IP to nat, I will use a vlan for this on the switch, :then can I use 7 ports on the switch along with my other external IPs ?
Are you asking about using the same switch for inside and outside network traffic, with the traffic kept seperate by VLANs? If so then generally Yes, you can do that, if your switch supports port-based VLANs, and if your security policy allows it. (Some security policies disallow such a thing, in order to prevent the possibility of "VLAN hopping" to bypass the PIX security.
If you are asking about using 7 different VLANs on the PIX 515, the answer is that you cannot do that in PIX 6.x, and would have to upgrade to PIX 7.x, which would likely require that you upgrade the memory on your PIX.
The PIX 515 Restricted license limits you to 3 VLANs in 6.x; the Unrestricted license limits you to 6 VLANs in 6.x.