my router connect in inside I have other subnet to reach Behind my Router (add 172.20.1.250) and i can ping to any subnet in outside
but not Behind my router but if i ping from my PIX it's Successful toward all subnet
I am connected in inside and my GW is 172.20.1.10
this is my config.
Honestly - it's a bad use of networking devices. The PIX is a "Firewall" to protect and give access between a trusted an un-trusted networks.
A router is a layer 3 IP routing device, design for routing IP subnet works.
If you have both devices available - then the router should be a router, the firewall should be a firewall. Only in cases where you only have one should you really make the devices duel purpose,
besides, your PIX was running 6.3 code - you would need to upgrade to 7.x or 8.x to do what you wanted to do, which would have been:-
static (inside,inside) 172.20.1.0 172.20.1.0 netmask 255.255.255.0
same-security-traffic permit intra-interface
the above would:-
1) Not nat any traffic from 172.20.1.0 to 172.20.1.0
2) Allow traffic recevied on the inside interface to be transmitted back out of the inside interface.
As you can see - the above is exactly 100% what a router does..... do you understand?