<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can the Pix Inside Interface route the traffic at the same s in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-the-pix-inside-interface-route-the-traffic-at-the-same/m-p/662822#M1031519</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello cindy,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sebastan is right.. u can have a look at this following URL for 7.x ASA's, which allow intra-interface traffic:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a0080734db7.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a0080734db7.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if u dont want to upgrade the pix to 7.x, i think the only possible solutions are the one discussed above in my post.. you can also think of investing on a L3 switch, if it makes sense on your network !!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let us know if you need any more help on this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Raj&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 22 Jan 2007 06:33:36 GMT</pubDate>
    <dc:creator>sachinraja</dc:creator>
    <dc:date>2007-01-22T06:33:36Z</dc:date>
    <item>
      <title>Can the Pix Inside Interface route the traffic at the same segment?</title>
      <link>https://community.cisco.com/t5/network-security/can-the-pix-inside-interface-route-the-traffic-at-the-same/m-p/662817#M1031507</link>
      <description>&lt;P&gt;Hi All, &lt;/P&gt;&lt;P&gt;I have a scenario here. &lt;/P&gt;&lt;P&gt;Try to connect a network range to the particular server but the gateway is pointing to the pix firewall interface. &lt;/P&gt;&lt;P&gt;Will the traffic works since the firewall interface is the same segment with the server? &lt;/P&gt;&lt;P&gt;i have attached the network diagram as attached. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:22:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-the-pix-inside-interface-route-the-traffic-at-the-same/m-p/662817#M1031507</guid>
      <dc:creator>cindylee27</dc:creator>
      <dc:date>2019-03-11T09:22:46Z</dc:date>
    </item>
    <item>
      <title>Re: Can the Pix Inside Interface route the traffic at the same s</title>
      <link>https://community.cisco.com/t5/network-security/can-the-pix-inside-interface-route-the-traffic-at-the-same/m-p/662818#M1031510</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi cindee&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I dont think the PIX will route the traffic on the same interface, as it received the traffic.. this was done for enhancing the security in PIX. which version of code are you running ?? I'm sure , with 6.x code this is not possible.. anyway, u can try out some options, to overcome your issue:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) If possible put a static route for 172.16.1.0/24 network on the server, to go directly to the router, instead of coming to the PIX... Is this the only network you are going to reach through the router A - router B link ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) or change the default gateway of the servers to the router ethernet interface. On the router, you can either configure static routes or route-maps (source based routing), for some subnets to reach the PIX... This will be a really good option...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) Put the router A on the DMZ port of the PIX, instead of connecting on inside.. by this, routing of packets will not be hindered.. but you gotta make sure of the configurations to be made in PIX, which increases administrative overhead !!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.. all the best.. rate replies if found useful..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Raj&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jan 2007 03:42:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-the-pix-inside-interface-route-the-traffic-at-the-same/m-p/662818#M1031510</guid>
      <dc:creator>sachinraja</dc:creator>
      <dc:date>2007-01-22T03:42:14Z</dc:date>
    </item>
    <item>
      <title>Re: Can the Pix Inside Interface route the traffic at the same s</title>
      <link>https://community.cisco.com/t5/network-security/can-the-pix-inside-interface-route-the-traffic-at-the-same/m-p/662819#M1031514</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Raj! &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But my problem here is the router A's routing is all pointing to the PIX Inside Interface, 10.10.6.1. Can i put a static route in the Router A to point directly to the SAP Server IP, 10.10.6.5??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will the network 172.16.1.0/24 go directly to 10.10.6.5 if the route is at ROuter A?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jan 2007 05:12:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-the-pix-inside-interface-route-the-traffic-at-the-same/m-p/662819#M1031514</guid>
      <dc:creator>cindylee27</dc:creator>
      <dc:date>2007-01-22T05:12:13Z</dc:date>
    </item>
    <item>
      <title>Re: Can the Pix Inside Interface route the traffic at the same s</title>
      <link>https://community.cisco.com/t5/network-security/can-the-pix-inside-interface-route-the-traffic-at-the-same/m-p/662820#M1031515</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi yes this can be done with the 7.2 code on the pix or asa. u need to give a command on the pix for same-security-traffic permit intra-interface which will allow packts entering and leaving the same interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this was basically made for hub and spoke vpn but in 7.2 code it will also allow clear text traffic. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hope this helps&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sebastan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jan 2007 05:34:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-the-pix-inside-interface-route-the-traffic-at-the-same/m-p/662820#M1031515</guid>
      <dc:creator>sebastan_bach</dc:creator>
      <dc:date>2007-01-22T05:34:36Z</dc:date>
    </item>
    <item>
      <title>Re: Can the Pix Inside Interface route the traffic at the same s</title>
      <link>https://community.cisco.com/t5/network-security/can-the-pix-inside-interface-route-the-traffic-at-the-same/m-p/662821#M1031517</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Sebastan,&lt;/P&gt;&lt;P&gt;The ver is 6.3.3. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any other ways to be done to allow this traffic as I could not move the network to another interface, it should come from the inside interface as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anything can be done on the router end ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jan 2007 06:15:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-the-pix-inside-interface-route-the-traffic-at-the-same/m-p/662821#M1031517</guid>
      <dc:creator>cindylee27</dc:creator>
      <dc:date>2007-01-22T06:15:27Z</dc:date>
    </item>
    <item>
      <title>Re: Can the Pix Inside Interface route the traffic at the same s</title>
      <link>https://community.cisco.com/t5/network-security/can-the-pix-inside-interface-route-the-traffic-at-the-same/m-p/662822#M1031519</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello cindy,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sebastan is right.. u can have a look at this following URL for 7.x ASA's, which allow intra-interface traffic:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a0080734db7.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a0080734db7.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if u dont want to upgrade the pix to 7.x, i think the only possible solutions are the one discussed above in my post.. you can also think of investing on a L3 switch, if it makes sense on your network !!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let us know if you need any more help on this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Raj&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jan 2007 06:33:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-the-pix-inside-interface-route-the-traffic-at-the-same/m-p/662822#M1031519</guid>
      <dc:creator>sachinraja</dc:creator>
      <dc:date>2007-01-22T06:33:36Z</dc:date>
    </item>
    <item>
      <title>Re: Can the Pix Inside Interface route the traffic at the same s</title>
      <link>https://community.cisco.com/t5/network-security/can-the-pix-inside-interface-route-the-traffic-at-the-same/m-p/662823#M1031520</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks guy..&lt;/P&gt;&lt;P&gt;Have solved the problem. The SAP Server def. gateway is actually pointing to the router interface instead. bravo! case close. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again..will rate helpful post.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Jan 2007 08:33:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-the-pix-inside-interface-route-the-traffic-at-the-same/m-p/662823#M1031520</guid>
      <dc:creator>cindylee27</dc:creator>
      <dc:date>2007-01-23T08:33:45Z</dc:date>
    </item>
  </channel>
</rss>

