03-12-2004 04:46 PM - edited 02-20-2020 11:17 PM
I have a PIX 501 with a Concentrator 3005 that establishes site VPN's to our other offices. When I setup static inside routes in the PIX to point to the Concentrator for my remote office LAN IP's I cannot route traffic. When a client on the PIX lan is using the PIX as the DG I cannot ping remote office. However if I add a static route in my Windows client the traffic routes correctly. Can someone tell me how to fix this?
Thanks,
Jason
03-12-2004 10:53 PM
Can you clarify the topology?
Are you saying you have an inside route on the and are trying a ping from an client off the inside interface to another inside client on the inside, but not a router hop away from the inside subnet? You can't have a request hit the PIX inside interface and be redirected back to another device on the inside. Traffic must traverse from one inteface of the PIX to another.
03-17-2004 06:20 AM
You will need an internal router to use as your DG. The "route inside" statements on the firewall are used to inform the firewall how to get to the other internal networks. The firewall cannot be used as a router as it cannot redirect traffic received on its internal interface back out the same interface.
Regards,
dk
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide