Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

PIX - funky routing/ARP

I need to put a PIX between a LAN and a router without changing the current LAN address of the router. I was thinking of doing the following:

Router (


PIX outside (

PIX inside (


LAN (172.16.x.x/16)

ip address outside

ip address inside

alias (inside)

static (inside,outside) netmask 500 400

access-list outside permit tcp any eq 25

access-group outside in interface outside

My theory is the alias command will allow the outbound access because the PIX will respond to ARP requests for the on the inside interface.

Also the inbound access to the mail server (.100) will work again because the PIX will answer the ARP even though the interface is not on the same subnet.

Comments please.

  • Other Security Subjects
New Member

Re: PIX - funky routing/ARP

Hi Nicholas,

I think there is 2 issues about your config :

First: The interfaces on the outside's subnet must be within the same IP range or you must manually enter routes to each other in the PIX and the router which isn't the best. Other solution, for the outside subnet, use on the router & on the PIX. Since this route is more specific than the rest of the 172.16/16 route, i hope the PIX will handle it correctly, like a router.

Second: You need the PIX does proxy-arping to answer to the host's gateway IP address ( Based on the following excerpt from Cisco's doc : "By default, the PIX Firewall responds to ARP requests directed at the PIX Firewall's interface IP addresses as well as to ARP requests for any static or global address defined on the PIX Firewall interface (which are proxy ARP requests)." You must make a global address or a static one. I'm not sure if the PIX will accept this, but you can try.

Finally, if the need to keep the router's inside IP address is just to keep host's gateway IP address the same, you can use the global or static hint for proxy-arping and configure another IP subnet, which isn't in conflict with inside range.



P.S.: If helps, don't forget to rate post.

This widget could not be displayed.