RE: [fw-wiz] PIX 500 as ROUTER ONLY

From: Wes Noonan (mailinglists_at_wjnconsulting.com)
Date: 11/24/03

  • Next message: Ravi Kumar: "Re: [fw-wiz] Private IP going outside of the firewall"
    To: "'Luca Berra'" <bluca@comedia.it>, <firewall-wizards@honor.icsalabs.com>
    Date: Sun, 23 Nov 2003 18:12:52 -0600
    
    

    That is the biggest reason I can think of for why not to use the PIX as a
    router. It can route, but it doesn't like to (and I don't think can) route
    packets back on the same interface.

    Wes Noonan

    > -----Original Message-----
    > From: firewall-wizards-admin@honor.icsalabs.com [mailto:firewall-wizards-
    > admin@honor.icsalabs.com] On Behalf Of Luca Berra
    > Sent: Saturday, November 22, 2003 08:32
    > To: firewall-wizards@honor.icsalabs.com
    > Subject: Re: [fw-wiz] PIX 500 as ROUTER ONLY
    >
    > On Thu, Nov 20, 2003 at 09:26:26PM -0800, Dario Calia wrote:
    > >Which PIX model do you have? The PIX supports static
    > >routing, Passive
    > >RIP and a very complete implementation of OSPF. What
    >
    > Dario,
    > correct me if i am wrong, the major difference in using a pix instead of
    > a router would be that the pix does not forward packets on the same
    > interface?
    >
    > --
    > Luca Berra -- bluca@comedia.it
    > Communication Media & Services S.r.l.
    > /"\
    > \ / ASCII RIBBON CAMPAIGN
    > X AGAINST HTML MAIL
    > / \
    > _______________________________________________
    > firewall-wizards mailing list
    > firewall-wizards@honor.icsalabs.com
    > http://honor.icsalabs.com/mailman/listinfo/firewall-wizards

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Ravi Kumar: "Re: [fw-wiz] Private IP going outside of the firewall"

    Relevant Pages

    • Re: Dual gateway configuration on ASA 5520
      ... have a default gateway on interface outside2, route ... PIX / ASA does not have source routing. ... The usual way of handling this sort of thing on PIX / ASA ... route to 10.3.x.x was through the outside2 interface so it would ...
      (comp.dcom.sys.cisco)
    • Re: Pix 501 and Local Network Router (No VPN Needed)
      ... If you are putting a router in between the PC's and the PIX then the inside ... interface of the PIX would have to be on a different subnet from the PC's. ... > fixup protocol dns maximum-length 512 ...
      (comp.dcom.sys.cisco)
    • Re: PIX 501 Basic Configuration
      ... :I have just been given a PIX 501 to configure and have very little ... :My configuration sounds simple, I do not want DHCP and I do not think I ... interface IP and you or your ISP must route the internal public IP subnet ... directing it to the inside router. ...
      (comp.dcom.sys.cisco)
    • Re: Cisco PIX 506
      ... This is my router configuration as it stands now. ... ip route 0.0.0.0 0.0.0.0 Serial0 ... access-list 101 deny ip 127.0.0.0 0.255.255.255 any log ... PIX questions are better addressed to comp.dcom.sys.cisco -- more PIX ...
      (comp.security.firewalls)
    • RE: Router with security features
      ... Subject: Router with security features ... Cisco makes an even cheaper and smaller pix firewall. ... Pix 520's it just does not come with more powerful hardware. ...
      (Security-Basics)