11-08-2007 05:53 AM - edited 02-21-2020 01:46 AM
I have the following topology
R1 --Lan--PIX--Lan---R2,R3,R4
I need to configure OSPF .should i pass the ospf through the PIX or configuring the ospf on the pix too? whot does cisco recommend?
11-08-2007 05:58 AM
Hi
Kind of depends on what mode the firewall is in. If the firewall is running in transparent mode then pass the OSPF traffic through. If it is running in routed mode it needs to participate in OSPF routing.
HTH
Jon
11-11-2007 01:28 AM
The FW is routed mode but is there any problem if i passed the traffic through it may be i need to use PBR on the inside routers
11-11-2007 02:07 AM
Hi
That is the problem. OSPF expects to form ajacencies with neighbours on the same network but you have another hop between your 2 ospf routers because the firewall is in routed mode. That is why you can run OSPF on the FWSM itself in routed mode to get around this problem.
The only way the 2 ospf routers on either side of your FWSM will see each as neighbours is if the FWSM is in transparent mode ie. the same subnet on either side of the FWSM.
Jon
11-11-2007 07:50 AM
Apologies, i keep referring to the FWSM (Firewall Services Module) but the same applies to the standalone pix.
Jon
11-14-2007 11:39 PM
Wouldn't it be possible to configure a GRE tunnel between the 2 routers through the FWSM/PIX/ASA (allowing the correct ports to go through of course) for OSPF traffic? Seems like that would enable the routers to see each other as neighbors.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: