<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX external IP and Router default gateway issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-external-ip-and-router-default-gateway-issue/m-p/671719#M1036490</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks sachinraja,sorry for my description,please see attachment you may have an idea, client have a banch of GRE brach talking to IPSec branch through a cisco router and a PIX in HQ.Now they move the Cisco router to another new location:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Old site:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX external IP:   199.243.ff.hh/29&lt;/P&gt;&lt;P&gt;ISP gateway IP (Default gateway): 199.243.ff.ii/29&lt;/P&gt;&lt;P&gt;Cisco2611 external IP:   199.243.ff.JJ/29&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;New site:&lt;/P&gt;&lt;P&gt;IP block: 38.99.aa.bb/29&lt;/P&gt;&lt;P&gt;PIX external IP:   38.99.xx.yy/30&lt;/P&gt;&lt;P&gt;ISP gateway IP (Default gateway): 38.99.xx.zz/30&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is how can I configure the Cisco router default route,if I use one of the address from IP aa.bb which is different subenet with xx.yy and xx.zz ?&lt;/P&gt;&lt;P&gt;In old site PIX, client router and ISP router in a same IP subnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 08 Dec 2006 02:18:59 GMT</pubDate>
    <dc:creator>pengfang</dc:creator>
    <dc:date>2006-12-08T02:18:59Z</dc:date>
    <item>
      <title>PIX external IP and Router default gateway issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-external-ip-and-router-default-gateway-issue/m-p/671717#M1036443</link>
      <description>&lt;P&gt;Here is the situation ,my client will move a Cisco router running GRE to a new site,the cisco router extenal IP ,PIX external IP and ISP router in same /29 subnet; the new IP scope is PIX and ISP router within a /30 ip scope and PIX can have /29 subnet IP for provide service for outside,but if I assign one of the IP from /29 Pool to Cisco router.How can I configure default gateway ?I can't point to ISP router,but can I point to PIX with one IP of the /29 scope and let PIX to route traffic to ISP router ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;------------ Private&lt;/P&gt;&lt;P&gt;  |                  |&lt;/P&gt;&lt;P&gt;PIX           Cisco 2611&lt;/P&gt;&lt;P&gt;  |                  |&lt;/P&gt;&lt;P&gt;----ISP router------ Internet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:05:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-external-ip-and-router-default-gateway-issue/m-p/671717#M1036443</guid>
      <dc:creator>pengfang</dc:creator>
      <dc:date>2019-03-11T09:05:39Z</dc:date>
    </item>
    <item>
      <title>Re: PIX external IP and Router default gateway issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-external-ip-and-router-default-gateway-issue/m-p/671718#M1036468</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hello Peng,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;really not sure of your requirement... Is the cisco router also on the outside segment with the internet router and you are assigning all these components an ip address from /29? If this is the case, then you need to point the default gateway from the PIX to the internet router and point specific routes from the PIX to the 2611 intranet router. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For eg, if u gotta reach subnet 172.16.1.0/24 through the GRE tunnel, you need to add the following routes:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 internet_router&lt;/P&gt;&lt;P&gt;ip route 172.16.1.0 255.255.255.0 intranet_router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let us know if this is what you wanted.. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Raj&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Dec 2006 23:07:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-external-ip-and-router-default-gateway-issue/m-p/671718#M1036468</guid>
      <dc:creator>sachinraja</dc:creator>
      <dc:date>2006-12-07T23:07:01Z</dc:date>
    </item>
    <item>
      <title>Re: PIX external IP and Router default gateway issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-external-ip-and-router-default-gateway-issue/m-p/671719#M1036490</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks sachinraja,sorry for my description,please see attachment you may have an idea, client have a banch of GRE brach talking to IPSec branch through a cisco router and a PIX in HQ.Now they move the Cisco router to another new location:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Old site:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX external IP:   199.243.ff.hh/29&lt;/P&gt;&lt;P&gt;ISP gateway IP (Default gateway): 199.243.ff.ii/29&lt;/P&gt;&lt;P&gt;Cisco2611 external IP:   199.243.ff.JJ/29&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;New site:&lt;/P&gt;&lt;P&gt;IP block: 38.99.aa.bb/29&lt;/P&gt;&lt;P&gt;PIX external IP:   38.99.xx.yy/30&lt;/P&gt;&lt;P&gt;ISP gateway IP (Default gateway): 38.99.xx.zz/30&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is how can I configure the Cisco router default route,if I use one of the address from IP aa.bb which is different subenet with xx.yy and xx.zz ?&lt;/P&gt;&lt;P&gt;In old site PIX, client router and ISP router in a same IP subnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Dec 2006 02:18:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-external-ip-and-router-default-gateway-issue/m-p/671719#M1036490</guid>
      <dc:creator>pengfang</dc:creator>
      <dc:date>2006-12-08T02:18:59Z</dc:date>
    </item>
    <item>
      <title>Re: PIX external IP and Router default gateway issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-external-ip-and-router-default-gateway-issue/m-p/671720#M1036504</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is diagram.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Dec 2006 02:25:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-external-ip-and-router-default-gateway-issue/m-p/671720#M1036504</guid>
      <dc:creator>pengfang</dc:creator>
      <dc:date>2006-12-08T02:25:08Z</dc:date>
    </item>
    <item>
      <title>Re: PIX external IP and Router default gateway issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-external-ip-and-router-default-gateway-issue/m-p/671721#M1036512</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Peng,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the components are in two different segments ie xx.zz &amp;amp; aa.bb, obviously you cannot put the default gateway in 2611 pointing to  xx.zz. you need to either put all these components on the same LAN (as in the old setup) or configure some kinda sub-interface/secondary IP addresses on the router to make them talk with two different subnets... To be precise, here is what u can do:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) put these components on the same LAN - probably get a new /28 from the ISP and solve your problem&lt;/P&gt;&lt;P&gt;2) configure secondary IP address on the main/core router (xx.zz) with an IP address from the aa.bb segment. You can configure the default gateway of 2611 router to be the secondary IP address configured.&lt;/P&gt;&lt;P&gt;3) you can configure sub-interfaces and configure trunk between the core - edge routers and give both the subnet information to the xx.zz router...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.. all the best.. rate replies if found useful..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Raj&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Dec 2006 02:45:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-external-ip-and-router-default-gateway-issue/m-p/671721#M1036512</guid>
      <dc:creator>sachinraja</dc:creator>
      <dc:date>2006-12-08T02:45:10Z</dc:date>
    </item>
    <item>
      <title>Re: PIX external IP and Router default gateway issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-external-ip-and-router-default-gateway-issue/m-p/671722#M1036516</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you have flexibility to use other option, putting the router in front of firewall (see diagram) will help you with the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With this, you can:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Maintain GRE on router and have it point to ISP router as default gateway to internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Router and PIX can use 2 of the Public IP to communicate, leaving 4 IPs to use.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- PIX can point to C2611 as default route to internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Protect/secure the whole internal segment with firewall sitting between router/internet and internal network. This is a realistic security design as with the previous setup, your C2611 router can be a backdoor to get into your network. Firewall placement in that sense is less effective.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My 2cent opinion.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;AK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Dec 2006 02:53:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-external-ip-and-router-default-gateway-issue/m-p/671722#M1036516</guid>
      <dc:creator>a.kiprawih</dc:creator>
      <dc:date>2006-12-08T02:53:44Z</dc:date>
    </item>
    <item>
      <title>Re: PIX external IP and Router default gateway issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-external-ip-and-router-default-gateway-issue/m-p/671723#M1036520</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here's the diagram. It was attached but  deleted as the tif format was not clear.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;AK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Dec 2006 02:57:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-external-ip-and-router-default-gateway-issue/m-p/671723#M1036520</guid>
      <dc:creator>a.kiprawih</dc:creator>
      <dc:date>2006-12-08T02:57:04Z</dc:date>
    </item>
    <item>
      <title>Re: PIX external IP and Router default gateway issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-external-ip-and-router-default-gateway-issue/m-p/671724#M1036522</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Raj for help.The Proplem is I can not touch the default gateway device managed by ISP.My idea are &lt;/P&gt;&lt;P&gt;1. If I don't modify topology,I can pick one of the IP from the pool such as 38.99.aa.cc/29 and assigned it to Cisco router, and another IP 38.99.aa.dd/29 assigned to PIX by&lt;/P&gt;&lt;P&gt;static (inside,outside) 38.99.aa.dd 192.168.10.1 # PIX inside IP#&lt;/P&gt;&lt;P&gt;then configure default route on C2611&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 38.99.aa.dd&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so traffic will hit PIX firstly and then be redirected to ISP router.&lt;/P&gt;&lt;P&gt;For the inbound traffic to the C2611,PIX will proxy arp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This just my analysis,not been tested, is it possile ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.I can put C2611 on the DMZ zone,and allow GRE pass through to DMZ,this should work and give C2611 some protection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea about my first guess ?&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Dec 2006 03:39:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-external-ip-and-router-default-gateway-issue/m-p/671724#M1036522</guid>
      <dc:creator>pengfang</dc:creator>
      <dc:date>2006-12-08T03:39:41Z</dc:date>
    </item>
    <item>
      <title>Re: PIX external IP and Router default gateway issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-external-ip-and-router-default-gateway-issue/m-p/671725#M1036523</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks AK your great idea, can you help me take a look my own solution I just posted and give some suggestion ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And if I put c2611 before PIX,after GRE terminated on c2611,I think branch office can not talk to inside network&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Dec 2006 03:41:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-external-ip-and-router-default-gateway-issue/m-p/671725#M1036523</guid>
      <dc:creator>pengfang</dc:creator>
      <dc:date>2006-12-08T03:41:34Z</dc:date>
    </item>
  </channel>
</rss>

