cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
273
Views
0
Helpful
2
Replies

Connect 2nd PIX firewall to router that connects to the internet/ISP

agrayson
Level 1
Level 1

Hello

I have a NS location connected to a SS location via T-1. I have a NS PIX515 6.3 and a SS PIX 525 6.3. The NS PIX is the original PIX and has been in place for a couple years. We have 2 internet connections 1 on the SS and 1 on the NS. The SS has the new PIX525 and the new internet connection. I want SS users to use SS internet and NS users to use NS internet. I need to know what config to use for the SS router connected to the ISP. The ISP for the SS internet connection only provides the circuit. I have a router conected to the IPS which is connected to the SS PIX which is connected to my internal core router. The NS internet connection is working but when I try to use the same config for the SS I can not connect to internet. I know the SS conection to the internet is good because I directly connected a laptop and it works. I was on a trouble call with Cisco for the PIX but he said it is not the PIX and a routing issue. I think it is how the Edge router to the SS ISP connection is configured. I am missing something. Heres a flow chart....inside core router...16.1>>>>>PIX5252..inside intf 16.3 PIX525 outside intf 199.xxx.86.177>>>Edge 2651 router 199.xxx.86.178 then out serial to ISP...63.xxx.59.137...........

1 Accepted Solution

Accepted Solutions

czrussel
Level 1
Level 1

If I understand your setup, both internet connection are working and there should be a router on each side of the T1, right? Is that router the default gateway for WS at NS? If so, set that router's default gateway to the PIX in the NS office. So any unknown routes will go the PIX bound for the internet. Make sure that the router in NS knows about all the networks in SS by static or dynamic routing.

View solution in original post

2 Replies 2

kschafer
Level 1
Level 1

From the SS site, can you connect through the PIX to the edge router ?

= K

czrussel
Level 1
Level 1

If I understand your setup, both internet connection are working and there should be a router on each side of the T1, right? Is that router the default gateway for WS at NS? If so, set that router's default gateway to the PIX in the NS office. So any unknown routes will go the PIX bound for the internet. Make sure that the router in NS knows about all the networks in SS by static or dynamic routing.