Cisco Support Community
Community Member

Secondary ip address to PIX interface


My set up of PIX and ISP router is like this : ISP router is using serial T1 link for internet connectivity for static (live) ip address. This router's eth0 has been connected to PIX outside interface. This interface is configured for one more internet static (live ) ip address. PIX outside interface is also configured for internet static ( live ) IP address. Users from inside use NAT and global command to use internet. so far so good. Now routers T1 link will be divided in two channels one will be used for internet use and another will be used for MPLS VPN with private addressing. Thus traffic leaving routers serial port will be for two different clouds one will be internet and another will be MPLS VPN cloud. Giving twp ip address on router serial and eth ports is done. But how can I configure PIX outside interface with 2 ip address one for NAT for internet and one for NAT or No-Nat (0) for traffiic heading for MPLS VPN cloud. This will logically connect 2 interfaces of PIX outside to 2 logical interfaces for routers eth0.


Community Member

Re: Secondary ip address to PIX interface

You need to use VALN's between the pix and upstream router.VLAN support for pix was introduced in 6.3 and supported in 7.0 as well, provided your upstream router supports VLAN's.



The following example configures parameters for a subinterface in single mode using VLAN101:

hostname(config)# interface gigabitethernet0/1.1

hostname(config-subif)# vlan 101

hostname(config-subif)# nameif dmz1

hostname(config-subif)# security-level 50

hostname(config-subif)# ip address

hostname(config-subif)# no shutdown

Community Member

Re: Secondary ip address to PIX interface

Thanx. Mr. varakantam.

Similar to vlan 101 as given in ur reply. It will be possible to configure vlan 102 for some totally different network id. Then eth0 ( outside ) this will be connected to ethernet port of router. In this case I need to configure 2 corresponding sub interfaces on router and enable routing in between them. Do i need to to any separate encapsulation like ISL or 802.1q just like we do in switch trunk configuration.

I would appreciate if you can please let me know any link on cisco website for similar configuration ?


Community Member

Re: Secondary ip address to PIX interface

Yes absolutely you may configure a second VLAN. Refer to the following guide for documentaton and implementaton.

CreatePlease to create content