Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Cisco 515e PIX Firewall: Route only port 80 and 443 traffic

I have a PIX 515e firewall with 3 interfaces (Inside, ISP_1, ISP_2). I currently have everything routed to ISP_1 but I would like to route all Web Browsing traffic (port 80 and 443) to ISP_2 and all other traffic continue out ISP_1.

I have setup an ACL specifying all traffic going to 0.0.0.0 on port 80 and 443 to use ISP_2. But for some reason when I do that, that ACL rule reverts back to ISP_1. I am using the PIX PDM GUI.

Also, I do not have a static route defined for the ISP_2 interface, only an ACL. I am not sure how to define that route since I already have one ISP_1. Would it be somehthing like this?

<local network> <Local subnet> route to <ISP_1>

<local network> <Local subnet> route to <ISP_2>

I am not sure how the above would work. I still want all non port 80 and 443 traffic to go out through ISP_1.

Your help is appreciated.

4 REPLIES

Re: Cisco 515e PIX Firewall: Route only port 80 and 443 traffic

I'm afraid you can't do that with a PIX. You could do it with a router and a route map.

New Member

Re: Cisco 515e PIX Firewall: Route only port 80 and 443 traffic

So would I need 2 Firewalls then, for each ISP connection?

Also is a layer 3 Cisco switch able to route map?

New Member

Re: Cisco 515e PIX Firewall: Route only port 80 and 443 traffic

Correct you need two firewalls.

Yes, you can route-map with a L3 cisco switch.

you would use the route map with an extended access-list to push the traffic to the specific firewall. Google "cisco route-map" for examples

Re: Cisco 515e PIX Firewall: Route only port 80 and 443 traffic

If you want to differentiate traffic flows then yes. You could use one router and connect to both ISPs and do the route map (as well as firewall services). I believe that route map support on L3 switches depends on the platform and Enhance Image IOS.

297
Views
0
Helpful
4
Replies