Configuration:
PIX 515E w/6.2.1
Inside: 1.2.3.224/28 (e1 IF = 1.2.3.225)
DMZ: 1.2.3.240/28 (e2 IF = 1.2.3.241)
No translation all static.
I >accidentally< had a >Windows ME< computer on the Inside IF with the following config:
IP: 1.2.3.250 <<<<< out of range
Mask: 255.255.255.240
Gateway: 1.2.3.225 <<<< or this is out of range
The OS didnt complain about the ip/gateway not being in the same range, but in any event, the config worked there was connectivity to the outside. (http://www.whatismyip resulted in 1.2.3.250).
Is this supposed to work? If so, its a feature! In the above scenario, I am wasting ips on the dmz that I would like to use on the inside. Why/how is the PIX allowing traffic from an IP on an interface that conflicts with another route/interface?
-Mike Baranowski