I have a PIX 515E - the DMZ port is not used presently. I am changing ISPs. I already have the new ISP components connected and running as advertised. I want to verify all is going to work correctly with my static routes and the new ISP before cancelling the old ISP. I am wanting to connect the new ISP to the DMZ port to test the static routes. Is this possible and if so, what type of additional statements should to be added to give the DMZ FULL access to the network?
First PIX ver 6.x does not support dual ISP. In order to test if the second ISP is working correctly what you have to do is the below.
1- Give the DMZ interface an IP on the new ISP subnet
ip address DMZ "IP ON NEW SUBNET"
2- NAT inside users on the DMZ for testing:
no global (outside) 1 2XX.XXX.XXX.XXX nat
no (inside) 1 1XX.0.0.0 255.255.255.0 0 0
global (DMZ) 2 "New Public Subnet"
nat (inside) 2 1XX.0.0.0 255.255.255.0 0 0
3- Change the routing to point to the new ISP:
no route outside 0.0.0.0 0.0.0.0 2XX.XXX.XXX.XXX 1
route outside 0.0.0.0 0.0.0.0 "New ISP Gateway"
4- Clear xlate
After done with the testing swap the config back to the old ISP.
Please note that the above will cause down time so it is better to do the test after working hours,
Please let me know if you need further assistance,
Appreciate your rating,