PIX 506 static route

PIX 506 static route

NewsGroups | Search | Tools
 comp.dcom.sys.cisco  Post an article  get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content  add this group's latest topics to your Google content  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
PIX 506 static route Xbs 10-11-2006
Posted by Xbs on October 11, 2006, 6:19 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi,
I have 2 gateways in my network: 1 Cisco PIX 506 (10.171.206.1) and Ipcop
(10.171.206.2) with a DMZ (on the Ipcop) where the mail server resides
(192.168.0.4).

I just would like that a computer with the PIX defined as default Gateway
could access the mail server on the IPCop's DMZ

I Thougth about adding a static route on the PIX like:
route 192.168.0.1 255.255.255.0 10.71.206.2 1

It doesn't seem to be enough as the mail server doesn't answer the pings.

What did I miss here???
Note: it worked perfectly with another Ipcop instead of the PIX
Thanks in advance for our help



Network Magic 20% Off NMEASY coupon code spring banner 468x60
Posted by Walter Roberson on October 11, 2006, 11:50 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

>I have 2 gateways in my network: 1 Cisco PIX 506 (10.171.206.1) and Ipcop
>(10.171.206.2) with a DMZ (on the Ipcop) where the mail server resides
>(192.168.0.4).

>I just would like that a computer with the PIX defined as default Gateway
>could access the mail server on the IPCop's DMZ

>I Thougth about adding a static route on the PIX like:
>route 192.168.0.1 255.255.255.0 10.71.206.2 1

>It doesn't seem to be enough as the mail server doesn't answer the pings.

>What did I miss here???

PIX 4/5/6 never allows packets to return to the same [logical] interface
they reached the PIX by. PIX 7 sometimes does, but only when at
least one VPN is involved.

Upgrade your PIX to 6.3(3) or later and construct a logical interface
overlaying your inside interface and give the logical interface
an address directly in the 192.168.0 network, bypassing IPCOP. Or
if you want to keep IPCOP there, assign it a new address range
such as 192.168.1.2/24 and put the logical interface in that network
and add the route to 192.168.0.0 255.255.255.0 through 192.168.1.2

Posted by Walter Roberson on October 11, 2006, 11:51 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

>Upgrade your PIX to 6.3(3) or later and construct a logical interface
>overlaying your inside interface and give the logical interface

I forgot to mention that this will require using a LAN switch
that is 802.1Q VLAN aware.

Posted by Dave on October 12, 2006, 5:07 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Thanks a lot, I'll consider upgrading

>
> >Upgrade your PIX to 6.3(3) or later and construct a logical interface
> >overlaying your inside interface and give the logical interface
>
> I forgot to mention that this will require using a LAN switch
> that is 802.1Q VLAN aware.



Similar ThreadsPosted
What is the default precedence: local-route, static-route, OSPF-route? August 4, 2008, 3:00 am
Need to route SMTP traffic through static interface (not default route) March 27, 2007, 5:19 pm
Can netwrok run static route and dynamic route the same time? December 1, 2005, 1:18 pm
how to set a Static route in an 837 March 7, 2005, 8:38 pm
static route October 3, 2005, 6:15 am
Static Route that won't go away September 8, 2006, 11:18 am
Which is better - static route or NAT? September 26, 2006, 3:30 am
static route December 13, 2006, 11:53 am
Static Route December 20, 2007, 11:41 am
IOS: Static Route on Interface December 14, 2004, 9:00 pm

other useful resources:
The Federal Communications Commission (FCC)
Telecommunications Industry Association
Electronic and Software Security Products and Services
International Telecommunication Union

Custom CGI Perl and PHP programming by 1-Script.com

Contact Us | Privacy Policy
The site map in XML format XML site map