08-17-2006 06:52 AM - edited 03-03-2019 01:41 PM
Hi,
I wanted to make sure that is it posible for pix506e to do the routing, i.e can I use only Pix 506e at office with the 1 static route to internet and other is though ethernet cable to another network directly connected...
08-17-2006 07:37 AM
If by routing you mean direct data to a proper subnet via routes than yes. Dynamically routing on a PIX is available using OSPF... or you can simply just build static routes onto the PIX. Hope this helps.
-Mike
08-17-2006 09:45 AM
Thanks for your reply.
What I wanted to do is Connect pix directly to the Internet and another connections to local network(Direct ethernet connection)...
Is this possible ??????
08-17-2006 09:56 AM
Hi,
Yes. Outisde interface on the PIX connects to the Internet. Inside interface connects to your LAN.
Default (static) route on the PIX points to the next hop router via outside interface. If you have more than one subnet on your inside network, add static routes on the PIX for them to point to the next-hop router via the inside interface. Then configure all your access policies like NAT, access-list etc.
Here's a couple of links that you may find helpful and can answer most of your questions.
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_qanda_item09186a0080091b17.shtml
Good Luck!
Regards,
Sundar
08-18-2006 10:24 AM
One thing to clarify you can't re-route packets using PIX. This is because the PIX does not allow traffic to come from and exit the same interface at the same time.
For example:
Inside Interface: 192.168.1.254
Outside Interface: 67.67.66.67
You have an internal router: 192.168.1.253 with different branches behind it such as subnet 192.168.10.0
Now you can do a static route on the pix such as
route (inside) 192.168.10.0 255.255.255.0 192.168.1.253
Scenario 1:
A packet comes from 192.168.10.x headed to the internet the PIX will be able to deal with it because the destination is a public address.
Scenario 2:
A packet comes from 192.168.1.x and headed to 192.168.10.x
If the packet reaches the PIX as above it will drop the packet because PIX does not allow a packet to enter and exit the same interface!
I hope you got my point,
Let me know if this helps and rate please,
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide