A strange thing happened when we upgraded our PIX. We were using
PIX Version 6.3(1)
and upgraded to:
PIX Version 7.0(2)
We use Static PAT configurations to allow the outside world to communicate with machines in our DMZ. We then set up Dynamic PAT for connections going to the outside. We used seperate IPs for incoming vs outgoing and this worked well on 6.3. After upgrade (we replaced with a new PIX UNRESTRICTED w/ Version 7.0(2)), this functionality stopped working. NOW the oubound connections use the same IP address as the static PAT incoming.
Here is our config:
Outside | |