Ooops, made a bit of a mess of this. I didn't do this on site (the datacenter is too far away) - now I have a very early start b4 clients connect unless I can fix this on the PIX over SSH (which I can connect to)!
I've had a few issues with VLANs behind the firewall. There are x2: Vlan 2 (192.168.5.0/24) and Vlan 10 (10.0.0.0/24).
The Pix connects to a catalyst via a trunk which has both Vlans. The PIX DID have the inside interface of 192.168.5.1 and the catalyst had the default VLAN2.
I simply changed the default VLAN on the catalyst to VLAN10 (this kicked me off the VPN which I expected). I then thought I could login over SSH on the firewall change the internal interface to 10.0.0.1 and everything would be fine. I did this - but no joy. Eveything is down. I think this is because the route on the catalyst is still pointing to the 192.168.5.1 address.
Aaahh! Anything I can do? I've added a logical address in VLAN 2 with the 192.168.5.1 address - still no joy! Do I have to make the physical address of 10.0.0.0 have a lower security level than the logical VLAN2 address?
No. I can ping but I don't think the catalyst can pass anything else. Its got the right native VLAN but the wrong gateway (192.168.5.1) - which is now on as a virtual iterface on the PIX but it still isn't playing ball. Looks like an early one for me as well to go an change the switch locally.
DocumentationCode download linksGoalRequirementLimitationsSupported ISR and UCS-E ModelSupported ISRG2 and UCS-E Blades:Supported ISR4K and UCS-E Blades:Step by Step ConfigurationConfigure one of the connectivity options to access the Cisco IMC from the n...
Firepower Threat Defense (NGFWv) on UCS E-series - Transparent Mode in HA
DocumentationCode download linksGoalRequirementLimitationsSupported ISR and UCS-E ModelSupported ISRG2 and UCS-E Blades:Supported ISR4K and UCS-E Blades:Step by Step ConfigurationCo...
I am currently unable to specify "crypto keyring" command when configuring VPN connection on my cisco 2901 router.
The following licenses have been activated on my router :