<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Access to Internet For VLAN in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/access-to-internet-for-vlan/m-p/656852#M1028501</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Guess that didn't work after all.  Sometimes it works, sometimes it doesn't - I guess it depends upon which route it chooses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there another way to define the route for each VLAN?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 20 Jan 2007 06:50:51 GMT</pubDate>
    <dc:creator>bhoops</dc:creator>
    <dc:date>2007-01-20T06:50:51Z</dc:date>
    <item>
      <title>Access to Internet For VLAN</title>
      <link>https://community.cisco.com/t5/network-security/access-to-internet-for-vlan/m-p/656840#M1028482</link>
      <description>&lt;P&gt;How would I go about allowing a VLAN full access to the internet through a PIX.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Outside Interface: 88.88.88.88&lt;/P&gt;&lt;P&gt;Inside Interface: 10.36.1.1&lt;/P&gt;&lt;P&gt;Vlan35: 10.35.1.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Version 6.3(3)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have very limited PIX knowledge, so any help would be appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:22:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-to-internet-for-vlan/m-p/656840#M1028482</guid>
      <dc:creator>bhoops</dc:creator>
      <dc:date>2019-03-11T09:22:03Z</dc:date>
    </item>
    <item>
      <title>Re: Access to Internet For VLAN</title>
      <link>https://community.cisco.com/t5/network-security/access-to-internet-for-vlan/m-p/656841#M1028484</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Too many assumptions. Please sanitize and post your config.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Jan 2007 16:44:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-to-internet-for-vlan/m-p/656841#M1028484</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2007-01-19T16:44:25Z</dc:date>
    </item>
    <item>
      <title>Re: Access to Internet For VLAN</title>
      <link>https://community.cisco.com/t5/network-security/access-to-internet-for-vlan/m-p/656842#M1028485</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry about that.  Current Pix config is attached.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VLAN Routing is being handled by the 3550 switch at 10.36.3.1 / 10.44.1.1 / 10.35.1.1 with &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip default-gateway 10.36.1.1&lt;/P&gt;&lt;P&gt;ip classless&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 10.36.1.1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently clients on VLAN 1 can access the outside, but VLANs 35 and 44 cannot.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From what I can see, if I send a ping from a device on VLAN35 the switch routes it to the Pix inside interface, but when the ping is returned it cannot reach that device from the inside interface. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The pix can ping the device through the VLAN interface, but not through the inside interface. It just seems like I'm missing something really simple here... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Jan 2007 17:04:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-to-internet-for-vlan/m-p/656842#M1028485</guid>
      <dc:creator>bhoops</dc:creator>
      <dc:date>2007-01-19T17:04:05Z</dc:date>
    </item>
    <item>
      <title>Re: Access to Internet For VLAN</title>
      <link>https://community.cisco.com/t5/network-security/access-to-internet-for-vlan/m-p/656843#M1028487</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;deleted&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Jan 2007 17:31:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-to-internet-for-vlan/m-p/656843#M1028487</guid>
      <dc:creator>bhoops</dc:creator>
      <dc:date>2007-01-19T17:31:58Z</dc:date>
    </item>
    <item>
      <title>Re: Access to Internet For VLAN</title>
      <link>https://community.cisco.com/t5/network-security/access-to-internet-for-vlan/m-p/656844#M1028488</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Everything looks good except that the following line:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group ServerVLAN_access_in in interface ServerVLAN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The command is OK, but you do not have an ACL named ServerVLAN_access_in. Because there is no ACL, a 'deny ip any any' is implied blocking all traffic. You could either remove the access-group command or create the ACL allowing whatever you need access to on the outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH and please rate.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Jan 2007 17:42:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-to-internet-for-vlan/m-p/656844#M1028488</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2007-01-19T17:42:41Z</dc:date>
    </item>
    <item>
      <title>Re: Access to Internet For VLAN</title>
      <link>https://community.cisco.com/t5/network-security/access-to-internet-for-vlan/m-p/656845#M1028489</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK.  I made some revisions to the config, but it still doesn't work.  Same issue as before.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also noticed that the static statements don't work -- I cannot access the servers from the outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Jan 2007 18:09:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-to-internet-for-vlan/m-p/656845#M1028489</guid>
      <dc:creator>bhoops</dc:creator>
      <dc:date>2007-01-19T18:09:36Z</dc:date>
    </item>
    <item>
      <title>Re: Access to Internet For VLAN</title>
      <link>https://community.cisco.com/t5/network-security/access-to-internet-for-vlan/m-p/656846#M1028491</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check your logs, they should help point us in the right direction. I'll check the statics.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Jan 2007 18:20:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-to-internet-for-vlan/m-p/656846#M1028491</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2007-01-19T18:20:08Z</dc:date>
    </item>
    <item>
      <title>Re: Access to Internet For VLAN</title>
      <link>https://community.cisco.com/t5/network-security/access-to-internet-for-vlan/m-p/656847#M1028492</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Statics look OK. What's the default gateway of your servers? From the PIX can you successfully ping the mail server?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Jan 2007 18:23:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-to-internet-for-vlan/m-p/656847#M1028492</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2007-01-19T18:23:11Z</dc:date>
    </item>
    <item>
      <title>Re: Access to Internet For VLAN</title>
      <link>https://community.cisco.com/t5/network-security/access-to-internet-for-vlan/m-p/656848#M1028495</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The server default gateway is the VLAN IP of the layer 3 switch, so 10.35.1.1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the Pix I can ping with&lt;/P&gt;&lt;P&gt;  ping mail&lt;/P&gt;&lt;P&gt;  ping ServerVLAN mail&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but cannot ping with &lt;/P&gt;&lt;P&gt;  ping inside mail&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Jan 2007 18:36:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-to-internet-for-vlan/m-p/656848#M1028495</guid>
      <dc:creator>bhoops</dc:creator>
      <dc:date>2007-01-19T18:36:03Z</dc:date>
    </item>
    <item>
      <title>Re: Access to Internet For VLAN</title>
      <link>https://community.cisco.com/t5/network-security/access-to-internet-for-vlan/m-p/656849#M1028496</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The GuestWLAN VLAN (44) works just fine after I added nat (GuestWLAN) 1 10.44.1.0 255.255.255.0 0 0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Jan 2007 18:46:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-to-internet-for-vlan/m-p/656849#M1028496</guid>
      <dc:creator>bhoops</dc:creator>
      <dc:date>2007-01-19T18:46:02Z</dc:date>
    </item>
    <item>
      <title>Re: Access to Internet For VLAN</title>
      <link>https://community.cisco.com/t5/network-security/access-to-internet-for-vlan/m-p/656850#M1028498</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So you then have a static route in the 3550 point to the Server_vlan interface on the PIX?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Jan 2007 21:12:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-to-internet-for-vlan/m-p/656850#M1028498</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2007-01-19T21:12:57Z</dc:date>
    </item>
    <item>
      <title>Re: Access to Internet For VLAN</title>
      <link>https://community.cisco.com/t5/network-security/access-to-internet-for-vlan/m-p/656851#M1028499</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Oh wow -- talk about focusing on the wrong place.  Here I was convinced that it was a PIX configuration issue and never reviewed the switch.  Doh!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had A route configured on the 3550 - &lt;/P&gt;&lt;P&gt;  ip route 0.0.0.0 0.0.0.0 10.36.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But never added the route for VLAN35 - &lt;/P&gt;&lt;P&gt;  ip route 0.0.0.0 0.0.0.0 10.35.1.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for pointing this out for me!  What a relief to have this resolved!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Jan 2007 04:16:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-to-internet-for-vlan/m-p/656851#M1028499</guid>
      <dc:creator>bhoops</dc:creator>
      <dc:date>2007-01-20T04:16:54Z</dc:date>
    </item>
    <item>
      <title>Re: Access to Internet For VLAN</title>
      <link>https://community.cisco.com/t5/network-security/access-to-internet-for-vlan/m-p/656852#M1028501</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Guess that didn't work after all.  Sometimes it works, sometimes it doesn't - I guess it depends upon which route it chooses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there another way to define the route for each VLAN?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Jan 2007 06:50:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-to-internet-for-vlan/m-p/656852#M1028501</guid>
      <dc:creator>bhoops</dc:creator>
      <dc:date>2007-01-20T06:50:51Z</dc:date>
    </item>
    <item>
      <title>Re: Access to Internet For VLAN</title>
      <link>https://community.cisco.com/t5/network-security/access-to-internet-for-vlan/m-p/656853#M1028502</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there a reason you're using the 3550 as the DG? It's a security vulnerability. Try setting the PIX as your DG.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jan 2007 14:57:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-to-internet-for-vlan/m-p/656853#M1028502</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2007-01-22T14:57:22Z</dc:date>
    </item>
  </channel>
</rss>

