[fw-wiz] Multiple world connections into PIX

From: DCSIM Subscriptions (IA) (DCSIMSUBS_at_ia.ngb.army.mil)
Date: 01/27/04

  • Next message: nathanial Rowland: "[fw-wiz] Help On "Stealth" Fire Walls"
    To: <firewall-wizards@honor.icsalabs.com>
    Date: Tue, 27 Jan 2004 16:50:39 -0600
    
    

    Greetings.

    I've run into an interesting problem on a PIX 515. Here's a makeshift
    diagram:

    Warning! ASCII art!

    outside_1
    --------------|-----| inside_1
                  | |-------
    outside_2 | PIX |
    --------------| |-------
    (Def. GW) |-----| inside_2

    LAN networks are NAT'd 10.x.
    "World" networks are real addresses.

    Effectively what I'm trying to do is make hosts on inside_1 use the
    outside_1 network and inside_2 hosts use outside_2. This would be
    considered policy routing on a Cisco router.

    So, when a connection is initiated from outside_1 to inside_1, it is built
    correctly, according to the log. However, when the return traffic is sent
    back through the PIX, it tries to go out the default gateway, which is
    outside_2, which does not have that connection established.

    I believe I have all the NAT rules and access lists correct, but the PIX
    keeps trying to use the same interface for outbound traffic.

    So far I have only tried to solve this in the PDM. I am hoping that there
    are some commands in the CLI that will solve my problem.

    Any ideas?

    - Lee
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: nathanial Rowland: "[fw-wiz] Help On "Stealth" Fire Walls"

    Relevant Pages

    • Re: Qwest Private Network & Pix
      ... It's traffic from these other networks that cannot get to 192.168.0.0. ... I did some reading of the Pix command reference and I'm wondering if this ... >> that is connected to other sites via a Qwest PRN (private network) VPN. ... >> access-group 110 in interface outside ...
      (comp.dcom.sys.cisco)
    • Re: Qwest Private Network & Pix
      ... add these networks to the nat-0 list. ... > that is connected to other sites via a Qwest PRN (private network) VPN. ... > this off so I could install a Pix. ... > interface configured with 192.168.0.1 and the outside interface as ...
      (comp.dcom.sys.cisco)
    • Re: Qwest Private Network & Pix
      ... For the remote networks to get to the inside network you need to define a ... nat exemption and allow the traffic to enter via the outside interface. ... > I did some reading of the Pix command reference and I'm wondering if this ...
      (comp.dcom.sys.cisco)
    • RE: [fw-wiz] Multiple world connections into PIX
      ... The capability for multiple routes is there for redundancy only, ... routes to outside_1 and outside_2 for the hosts that you wanna send there. ... I've run into an interesting problem on a PIX 515. ... "World" networks are real addresses. ...
      (Firewall-Wizards)
    • Re: PIX 515E CPU util at 98% with a compromised system on inside network
      ... All inside networks use a 172.16.x.x ip address space. ... That results in the Pix with 98% CPU util and it stops responding to requests from other inside networks resulting in a DoS to the other inside networks. ... The embryonic connection limit feature doesn't help here because it ...
      (comp.dcom.sys.cisco)