I have a customer who wants to allow EIGRP through the PIX. I have tried this in my lab (one router on PIX inside and another router on PIX outside) and can't get it to work. I also put the two routers on the same subnet (changed the IP address of one) and verified EIGRP was working correctly on each router.
Here's the relevant portions of the PIX config:
access-list outside permit icmp any any
access-list outside permit tcp any host 172.16.1.22 eq www
access-list outside permit eigrp any any
access-list outside permit ip any host 224.0.0.10
access-list inside permit ip any any
ip address outside 172.16.1.1 255.255.255.0
ip address inside 10.1.1.1 255.255.255.0
global (outside) 1 interface
nat (inside) 1 0.0.0.0 0.0.0.0 0 0
static (inside,outside) 172.16.1.22 10.1.1.2 netmask 255.255.255.255 0 0
static (inside,outside) 172.16.1.5 10.1.1.5 netmask 255.255.255.255 0 0
static (inside,outside) 224.0.0.10 224.0.0.10 netmask 255.255.255.255 0 0
access-group outside in interface outside
access-group inside in interface inside
I don't say this is a wise thing to do, I just want to know if it's possible. After all, the PIX accepts 'eigrp' as a keyword.