Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

stateful routing?

Hello!

We have a network that is connected to two ISPs through two PIX firewalls. Those firewalls are connected to a single router. Also we have a server connected to the same router.

Then a number of external users make their connections to our server from outside. Some of those connections go through ISP1 and PIX1 while the others go through ISP2 and PIX2.

The question is: how to configure router so that it route backward traffic to the right interface?

For instance: if incoming packet was from ISP1 then reply from server to client should go through PIX1 as well. If the router send reply through PIX2 the session will break hence PIX1 cannot track the session.

How to overcome the problem?

2 REPLIES
Silver

Re: stateful routing?

Cluster your firewalls. I don't know if this is possible with PIX firewall. Nokia/Checkpoint is able to do this. The router has a source/destination and does not track the firewall it received it packets from.

New Member

Re: stateful routing?

Clustering is not an option. Because PIXes are far away from each other.

977
Views
0
Helpful
2
Replies