<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Conectivity problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/conectivity-problem/m-p/697817#M1035360</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yeah I swapped it and it's showing up, up now, but not got any traffic passing, everything is up, up but inside can't see the www.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;GB-HOMENET-PIX-01# sh run&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;PIX Version 6.3(3)&lt;/P&gt;&lt;P&gt;interface ethernet0 100full&lt;/P&gt;&lt;P&gt;interface ethernet1 auto&lt;/P&gt;&lt;P&gt;interface ethernet2 auto shutdown&lt;/P&gt;&lt;P&gt;interface ethernet3 auto shutdown&lt;/P&gt;&lt;P&gt;interface ethernet4 auto shutdown&lt;/P&gt;&lt;P&gt;interface ethernet5 auto shutdown&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;nameif ethernet2 DMZ security50&lt;/P&gt;&lt;P&gt;nameif ethernet3 WAP security50&lt;/P&gt;&lt;P&gt;nameif ethernet4 NOT_USED4 security1&lt;/P&gt;&lt;P&gt;nameif ethernet5 NOT_USED5 security1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hostname GB-HOMENET-PIX-01&lt;/P&gt;&lt;P&gt;domain-name HOMENET&lt;/P&gt;&lt;P&gt;fixup protocol dns maximum-length 512&lt;/P&gt;&lt;P&gt;fixup protocol ftp 21&lt;/P&gt;&lt;P&gt;fixup protocol h323 h225 1720&lt;/P&gt;&lt;P&gt;fixup protocol h323 ras 1718-1719&lt;/P&gt;&lt;P&gt;fixup protocol http 80&lt;/P&gt;&lt;P&gt;fixup protocol rsh 514&lt;/P&gt;&lt;P&gt;fixup protocol rtsp 554&lt;/P&gt;&lt;P&gt;fixup protocol sip 5060&lt;/P&gt;&lt;P&gt;fixup protocol sip udp 5060&lt;/P&gt;&lt;P&gt;fixup protocol skinny 2000&lt;/P&gt;&lt;P&gt;fixup protocol smtp 25&lt;/P&gt;&lt;P&gt;fixup protocol sqlnet 1521&lt;/P&gt;&lt;P&gt;fixup protocol tftp 69&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging console debugging&lt;/P&gt;&lt;P&gt;icmp deny any outside&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu DMZ 1500&lt;/P&gt;&lt;P&gt;mtu WAP 1500&lt;/P&gt;&lt;P&gt;mtu NOT_USED4 1500&lt;/P&gt;&lt;P&gt;mtu NOT_USED5 1500&lt;/P&gt;&lt;P&gt;ip address outside 192.168.1.2 255.255.255.252&lt;/P&gt;&lt;P&gt;ip address inside 172.16.10.2 255.255.255.128&lt;/P&gt;&lt;P&gt;ip address DMZ 172.16.10.129 255.255.255.252&lt;/P&gt;&lt;P&gt;ip address WAP 172.16.11.1 255.255.255.252&lt;/P&gt;&lt;P&gt;no ip address NOT_USED4&lt;/P&gt;&lt;P&gt;no ip address NOT_USED5&lt;/P&gt;&lt;P&gt;ip audit info action alarm&lt;/P&gt;&lt;P&gt;ip audit attack action alarm&lt;/P&gt;&lt;P&gt;no failover&lt;/P&gt;&lt;P&gt;failover timeout 0:00:00&lt;/P&gt;&lt;P&gt;failover poll 15&lt;/P&gt;&lt;P&gt;no failover ip address outside&lt;/P&gt;&lt;P&gt;no failover ip address inside&lt;/P&gt;&lt;P&gt;no failover ip address DMZ&lt;/P&gt;&lt;P&gt;no failover ip address WAP&lt;/P&gt;&lt;P&gt;no failover ip address NOT_USED4&lt;/P&gt;&lt;P&gt;no failover ip address NOT_USED5&lt;/P&gt;&lt;P&gt;pdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 172.16.10.1-172.16.10.127 netmask 255.255.255.128&lt;/P&gt;&lt;P&gt;global (DMZ) 2 172.16.10.128-172.16.10.254 netmask 255.255.255.128&lt;/P&gt;&lt;P&gt;global (WAP) 3 172.16.11.2-172.16.11.127 netmask 255.255.255.128&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;nat (DMZ) 2 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;nat (WAP) 3 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 192.168.1.1 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00&lt;/P&gt;&lt;P&gt;timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ protocol tacacs+&lt;/P&gt;&lt;P&gt;aaa-server RADIUS protocol radius&lt;/P&gt;&lt;P&gt;aaa-server LOCAL protocol local&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 172.16.10.10 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server community public&lt;/P&gt;&lt;P&gt;no snmp-server enable traps&lt;/P&gt;&lt;P&gt;floodguard enable&lt;/P&gt;&lt;P&gt;fragment chain 1 outside&lt;/P&gt;&lt;P&gt;fragment chain 1 inside&lt;/P&gt;&lt;P&gt;telnet 172.16.10.0 255.255.255.128 inside&lt;/P&gt;&lt;P&gt;telnet timeout 30&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;terminal width 80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 22 Nov 2006 13:34:15 GMT</pubDate>
    <dc:creator>adampetherick</dc:creator>
    <dc:date>2006-11-22T13:34:15Z</dc:date>
    <item>
      <title>Conectivity problem</title>
      <link>https://community.cisco.com/t5/network-security/conectivity-problem/m-p/697814#M1035355</link>
      <description>&lt;P&gt;I'm currently setting up a PIX 515e at home as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cable Modem --&amp;gt; 2621 Router --&amp;gt; PIX --&amp;gt; Switch&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The inside port on the PIX is up,up however I can't get the outside to connect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are the config's for the interfaces:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2621:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FastEthernet0/1 is up, line protocol is down&lt;/P&gt;&lt;P&gt;  Hardware is AmdFE, address is 0007.eb78.0ba1 (bia 0007.eb78.0ba1)&lt;/P&gt;&lt;P&gt;  Internet address is 192.168.1.1/30&lt;/P&gt;&lt;P&gt;  MTU 1500 bytes, BW 100000 Kbit, DLY 100 usec,&lt;/P&gt;&lt;P&gt;     reliability 255/255, txload 1/255, rxload 1/255&lt;/P&gt;&lt;P&gt;  Encapsulation ARPA, loopback not set&lt;/P&gt;&lt;P&gt;  Keepalive set (10 sec)&lt;/P&gt;&lt;P&gt;  Full-duplex, 100Mb/s, 100BaseTX/FX&lt;/P&gt;&lt;P&gt;  ARP type: ARPA, ARP Timeout 04:00:00&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface ethernet0 "outside" is up, line protocol is down&lt;/P&gt;&lt;P&gt;  Hardware is i82559 ethernet, address is 0011.2013.641b&lt;/P&gt;&lt;P&gt;  IP address 192.168.1.2, subnet mask 255.255.255.252&lt;/P&gt;&lt;P&gt;  MTU 1500 bytes, BW 100000 Kbit full duplex&lt;/P&gt;&lt;P&gt;        0 packets input, 0 bytes, 0 no buffer&lt;/P&gt;&lt;P&gt;        Received 0 broadcasts, 0 runts, 0 giants&lt;/P&gt;&lt;P&gt;        0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;/P&gt;&lt;P&gt;        77 packets output, 4620 bytes, 0 underruns&lt;/P&gt;&lt;P&gt;        0 output errors, 0 collisions, 0 interface resets&lt;/P&gt;&lt;P&gt;        0 babbles, 0 late collisions, 0 deferred&lt;/P&gt;&lt;P&gt;        0 lost carrier, 0 no carrier&lt;/P&gt;&lt;P&gt;        input queue (curr/max blocks): hardware (128/128) software (0/0)&lt;/P&gt;&lt;P&gt;        output queue (curr/max blocks): hardware (0/1) software (0/1)&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 08:59:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/conectivity-problem/m-p/697814#M1035355</guid>
      <dc:creator>adampetherick</dc:creator>
      <dc:date>2019-03-11T08:59:03Z</dc:date>
    </item>
    <item>
      <title>Re: Conectivity problem</title>
      <link>https://community.cisco.com/t5/network-security/conectivity-problem/m-p/697815#M1035358</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Adam&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which cable you are using to connect both PIX and the router ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you using cross over or a straight through cable ? Can you change the cable and check ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regds&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Nov 2006 04:59:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/conectivity-problem/m-p/697815#M1035358</guid>
      <dc:creator>spremkumar</dc:creator>
      <dc:date>2006-11-22T04:59:34Z</dc:date>
    </item>
    <item>
      <title>Re: Conectivity problem</title>
      <link>https://community.cisco.com/t5/network-security/conectivity-problem/m-p/697816#M1035359</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Since this only involved line protocol, check the UTP cable type you used to connect the router and PIX? It should be cross-over cable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;AK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Nov 2006 05:15:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/conectivity-problem/m-p/697816#M1035359</guid>
      <dc:creator>a.kiprawih</dc:creator>
      <dc:date>2006-11-22T05:15:06Z</dc:date>
    </item>
    <item>
      <title>Re: Conectivity problem</title>
      <link>https://community.cisco.com/t5/network-security/conectivity-problem/m-p/697817#M1035360</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yeah I swapped it and it's showing up, up now, but not got any traffic passing, everything is up, up but inside can't see the www.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;GB-HOMENET-PIX-01# sh run&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;PIX Version 6.3(3)&lt;/P&gt;&lt;P&gt;interface ethernet0 100full&lt;/P&gt;&lt;P&gt;interface ethernet1 auto&lt;/P&gt;&lt;P&gt;interface ethernet2 auto shutdown&lt;/P&gt;&lt;P&gt;interface ethernet3 auto shutdown&lt;/P&gt;&lt;P&gt;interface ethernet4 auto shutdown&lt;/P&gt;&lt;P&gt;interface ethernet5 auto shutdown&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;nameif ethernet2 DMZ security50&lt;/P&gt;&lt;P&gt;nameif ethernet3 WAP security50&lt;/P&gt;&lt;P&gt;nameif ethernet4 NOT_USED4 security1&lt;/P&gt;&lt;P&gt;nameif ethernet5 NOT_USED5 security1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hostname GB-HOMENET-PIX-01&lt;/P&gt;&lt;P&gt;domain-name HOMENET&lt;/P&gt;&lt;P&gt;fixup protocol dns maximum-length 512&lt;/P&gt;&lt;P&gt;fixup protocol ftp 21&lt;/P&gt;&lt;P&gt;fixup protocol h323 h225 1720&lt;/P&gt;&lt;P&gt;fixup protocol h323 ras 1718-1719&lt;/P&gt;&lt;P&gt;fixup protocol http 80&lt;/P&gt;&lt;P&gt;fixup protocol rsh 514&lt;/P&gt;&lt;P&gt;fixup protocol rtsp 554&lt;/P&gt;&lt;P&gt;fixup protocol sip 5060&lt;/P&gt;&lt;P&gt;fixup protocol sip udp 5060&lt;/P&gt;&lt;P&gt;fixup protocol skinny 2000&lt;/P&gt;&lt;P&gt;fixup protocol smtp 25&lt;/P&gt;&lt;P&gt;fixup protocol sqlnet 1521&lt;/P&gt;&lt;P&gt;fixup protocol tftp 69&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging console debugging&lt;/P&gt;&lt;P&gt;icmp deny any outside&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu DMZ 1500&lt;/P&gt;&lt;P&gt;mtu WAP 1500&lt;/P&gt;&lt;P&gt;mtu NOT_USED4 1500&lt;/P&gt;&lt;P&gt;mtu NOT_USED5 1500&lt;/P&gt;&lt;P&gt;ip address outside 192.168.1.2 255.255.255.252&lt;/P&gt;&lt;P&gt;ip address inside 172.16.10.2 255.255.255.128&lt;/P&gt;&lt;P&gt;ip address DMZ 172.16.10.129 255.255.255.252&lt;/P&gt;&lt;P&gt;ip address WAP 172.16.11.1 255.255.255.252&lt;/P&gt;&lt;P&gt;no ip address NOT_USED4&lt;/P&gt;&lt;P&gt;no ip address NOT_USED5&lt;/P&gt;&lt;P&gt;ip audit info action alarm&lt;/P&gt;&lt;P&gt;ip audit attack action alarm&lt;/P&gt;&lt;P&gt;no failover&lt;/P&gt;&lt;P&gt;failover timeout 0:00:00&lt;/P&gt;&lt;P&gt;failover poll 15&lt;/P&gt;&lt;P&gt;no failover ip address outside&lt;/P&gt;&lt;P&gt;no failover ip address inside&lt;/P&gt;&lt;P&gt;no failover ip address DMZ&lt;/P&gt;&lt;P&gt;no failover ip address WAP&lt;/P&gt;&lt;P&gt;no failover ip address NOT_USED4&lt;/P&gt;&lt;P&gt;no failover ip address NOT_USED5&lt;/P&gt;&lt;P&gt;pdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 172.16.10.1-172.16.10.127 netmask 255.255.255.128&lt;/P&gt;&lt;P&gt;global (DMZ) 2 172.16.10.128-172.16.10.254 netmask 255.255.255.128&lt;/P&gt;&lt;P&gt;global (WAP) 3 172.16.11.2-172.16.11.127 netmask 255.255.255.128&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;nat (DMZ) 2 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;nat (WAP) 3 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 192.168.1.1 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00&lt;/P&gt;&lt;P&gt;timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ protocol tacacs+&lt;/P&gt;&lt;P&gt;aaa-server RADIUS protocol radius&lt;/P&gt;&lt;P&gt;aaa-server LOCAL protocol local&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 172.16.10.10 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server community public&lt;/P&gt;&lt;P&gt;no snmp-server enable traps&lt;/P&gt;&lt;P&gt;floodguard enable&lt;/P&gt;&lt;P&gt;fragment chain 1 outside&lt;/P&gt;&lt;P&gt;fragment chain 1 inside&lt;/P&gt;&lt;P&gt;telnet 172.16.10.0 255.255.255.128 inside&lt;/P&gt;&lt;P&gt;telnet timeout 30&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;terminal width 80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Nov 2006 13:34:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/conectivity-problem/m-p/697817#M1035360</guid>
      <dc:creator>adampetherick</dc:creator>
      <dc:date>2006-11-22T13:34:15Z</dc:date>
    </item>
    <item>
      <title>Re: Conectivity problem</title>
      <link>https://community.cisco.com/t5/network-security/conectivity-problem/m-p/697818#M1035361</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;2 questions:&lt;/P&gt;&lt;P&gt;Do you have a route on your 2600 router pointing the 172.x.x.x to the pix?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip route 172.16.10.0 255.255.255.0 192.168.1.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why are you using a router at all?  You should be able to plug the PIX directly into the cable modem.  Set the PIX outside IP to use DHCP and nat to your external interface on the PIX.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Nov 2006 20:53:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/conectivity-problem/m-p/697818#M1035361</guid>
      <dc:creator>dflick</dc:creator>
      <dc:date>2006-11-22T20:53:14Z</dc:date>
    </item>
    <item>
      <title>Re: Conectivity problem</title>
      <link>https://community.cisco.com/t5/network-security/conectivity-problem/m-p/697819#M1035362</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think you need to change the 'global' IP. You should use Public IP here, i.e 192.168.1.x, instead of 172.16.10.x range.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Global is always associated with Public IP when it comes to outside/Internet connectivity. But since your Public IP has 2 hosts for Internet router FastEthernet facing PIX Outside interface (192.168.1.1) and PIX Outside interface (192.168.1.2), you have no choice here but to use Outside interface IP as global. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Use 'global' command with 'keyword' interface to allow internal users/DMZ to go out to Internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*192.168.1.0/30 means:&lt;/P&gt;&lt;P&gt;subnet ID: 192.168.1.0&lt;/P&gt;&lt;P&gt;Usable address: 192.168.1.1 - .2&lt;/P&gt;&lt;P&gt;broadcast ID: 192.168.1.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your config:&lt;/P&gt;&lt;P&gt;ip address outside 192.168.1.2 255.255.255.252  ---&amp;gt; note this for Outside&lt;/P&gt;&lt;P&gt;ip address inside 172.16.10.2 255.255.255.128  --&amp;gt; internal subnet&lt;/P&gt;&lt;P&gt;ip address DMZ 172.16.10.129 255.255.255.252 &lt;/P&gt;&lt;P&gt;ip address WAP 172.16.11.1 255.255.255.252 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 172.16.10.1-172.16.10.127 netmask 255.255.255.128 &lt;/P&gt;&lt;P&gt;global (DMZ) 2 172.16.10.128-172.16.10.254 netmask 255.255.255.128 &lt;/P&gt;&lt;P&gt;global (WAP) 3 172.16.11.2-172.16.11.127 netmask 255.255.255.128 &lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0 &lt;/P&gt;&lt;P&gt;nat (DMZ) 2 0.0.0.0 0.0.0.0 0 0 &lt;/P&gt;&lt;P&gt;nat (WAP) 3 0.0.0.0 0.0.0.0 0 0 &lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 192.168.1.1 1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Update:&lt;/P&gt;&lt;P&gt;- Remove the exisitng "global (outside) 1 172.16.10.1-172.16.10.127 netmask 255.255.255.128", and changed with:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This should work. Just make sure both of your PIX and Internet router can ping each other.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps. Pls rate all useful post(s)&lt;/P&gt;&lt;P&gt;AK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Nov 2006 23:41:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/conectivity-problem/m-p/697819#M1035362</guid>
      <dc:creator>a.kiprawih</dc:creator>
      <dc:date>2006-11-22T23:41:03Z</dc:date>
    </item>
    <item>
      <title>Re: Conectivity problem</title>
      <link>https://community.cisco.com/t5/network-security/conectivity-problem/m-p/697820#M1035363</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My public facing IP is 84.x.x.x which is assigned by my ISP via DHCP.;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have got the PIX and router pinging each other now but still no axs to the web&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Nov 2006 17:26:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/conectivity-problem/m-p/697820#M1035363</guid>
      <dc:creator>adampetherick</dc:creator>
      <dc:date>2006-11-23T17:26:03Z</dc:date>
    </item>
    <item>
      <title>Re: Conectivity problem</title>
      <link>https://community.cisco.com/t5/network-security/conectivity-problem/m-p/697821#M1035364</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's working now, thanks to dflick advising to get rid of the outside router and using ip address outside setroute.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's a lot slower now tho than the linksys box I was using before!! &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Nov 2006 20:27:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/conectivity-problem/m-p/697821#M1035364</guid>
      <dc:creator>adampetherick</dc:creator>
      <dc:date>2006-11-23T20:27:52Z</dc:date>
    </item>
  </channel>
</rss>

