<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Configuring PIX for a new interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/configuring-pix-for-a-new-interface/m-p/516083#M498404</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you routing 10.255.0.x/24 properly such that the 192.168.0.x hosts will send the traffic to the pix for that subnet?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Run this debug while pinging  from the DR box:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug packet DRSite&lt;/P&gt;&lt;P&gt;term mon&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and see if you see the pings hitting the pix.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 17 Aug 2006 20:01:34 GMT</pubDate>
    <dc:creator>mmorris11</dc:creator>
    <dc:date>2006-08-17T20:01:34Z</dc:date>
    <item>
      <title>Configuring PIX for a new interface</title>
      <link>https://community.cisco.com/t5/network-security/configuring-pix-for-a-new-interface/m-p/516077#M498398</link>
      <description>&lt;P&gt;I am attempting to set up a new interface on our PIX 525E so that we can replicate data over it for a disaster recovery site.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Internal addresses: 10.0.0.0 255.0.0.0&lt;/P&gt;&lt;P&gt;DR Site addresses: 192.168.0.0 255.255.255.0&lt;/P&gt;&lt;P&gt;External address: aaa.bbb.ccc.xxx (for privacy)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've gone through the steps listed for configuring a PIX with multiple interfaces with NAT and PAT, but the traffic still isn't flowing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We use VLANs on the internal network, but I don't think they affect the firewall or its interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's the config:&lt;/P&gt;&lt;P&gt;PIX Version 6.3(3)&lt;/P&gt;&lt;P&gt;interface ethernet0 auto&lt;/P&gt;&lt;P&gt;interface ethernet1 auto&lt;/P&gt;&lt;P&gt;interface ethernet2 auto&lt;/P&gt;&lt;P&gt;interface ethernet3 auto&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;nameif ethernet2 dmz security4&lt;/P&gt;&lt;P&gt;nameif ethernet3 DRSite security90&lt;/P&gt;&lt;P&gt;hostname FIREWALL&lt;/P&gt;&lt;P&gt;domain-name xxxxxxx.com&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;name 10.0.0.26 neoteris&lt;/P&gt;&lt;P&gt;name 10.0.0.24 FP02&lt;/P&gt;&lt;P&gt;name 10.0.0.60 exchange&lt;/P&gt;&lt;P&gt;name 10.0.0.31 citrix&lt;/P&gt;&lt;P&gt;access-list dmz_access_in permit tcp any host aaa.bbb.ccc.106 eq citrix-ica &lt;/P&gt;&lt;P&gt;access-list dmz_access_in permit tcp any host aaa.bbb.ccc.105 eq smtp &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any host aaa.bbb.ccc.106 eq citrix-ica &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any host aaa.bbb.ccc.106 eq www &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any host aaa.bbb.ccc.107 eq www &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any host aaa.bbb.ccc.106 eq https &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any host aaa.bbb.ccc.107 eq https &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any host aaa.bbb.ccc.105 eq smtp &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit icmp any any &lt;/P&gt;&lt;P&gt;access-list inside_access_in permit tcp any any &lt;/P&gt;&lt;P&gt;access-list inside_access_in permit ip any any &lt;/P&gt;&lt;P&gt;access-list dmz_outbound_nat0_acl permit ip any any &lt;/P&gt;&lt;P&gt;access-list inside_outbound_nat0_acl permit ip 10.0.0.0 255.0.0.0 192.168.0.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list DRSite_access_in permit tcp any any &lt;/P&gt;&lt;P&gt;access-list DRSite_access_in permit udp any any &lt;/P&gt;&lt;P&gt;access-list DRSite_access_in permit ip any any &lt;/P&gt;&lt;P&gt;access-list DRSite_access_in permit icmp any any &lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu dmz 1500&lt;/P&gt;&lt;P&gt;mtu DRSite 1500&lt;/P&gt;&lt;P&gt;ip address outside aaa.bbb.ccc.2 255.255.255.0&lt;/P&gt;&lt;P&gt;ip address inside 10.255.0.254 255.255.255.0&lt;/P&gt;&lt;P&gt;ip address dmz 38.112.5.138 255.255.255.252&lt;/P&gt;&lt;P&gt;ip address DRSite 192.168.0.1 255.255.255.0&lt;/P&gt;&lt;P&gt;ip verify reverse-path interface outside&lt;/P&gt;&lt;P&gt;pdm location citrix 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;pdm location exchange 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;pdm location FP02 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;pdm location 10.0.0.0 255.255.0.0 inside&lt;/P&gt;&lt;P&gt;pdm location 10.3.0.0 255.255.224.0 inside&lt;/P&gt;&lt;P&gt;pdm location 10.0.0.0 255.0.0.0 inside&lt;/P&gt;&lt;P&gt;pdm location 192.168.0.0 255.255.0.0 DRSite&lt;/P&gt;&lt;P&gt;pdm location 192.168.0.2 255.255.255.255 DRSite&lt;/P&gt;&lt;P&gt;pdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;global (dmz) 1 interface&lt;/P&gt;&lt;P&gt;global (DRSite) 1 192.168.0.2-192.168.0.200&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list inside_outbound_nat0_acl&lt;/P&gt;&lt;P&gt;nat (inside) 1 10.0.0.0 255.0.0.0 0 0&lt;/P&gt;&lt;P&gt;nat (dmz) 0 access-list dmz_outbound_nat0_acl&lt;/P&gt;&lt;P&gt;nat (DRSite) 1 192.168.0.0 255.255.255.0 0 0&lt;/P&gt;&lt;P&gt;static (inside,dmz) aaa.bbb.ccc.107 neoteris netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;static (inside,outside) aaa.bbb.ccc.107 neoteris netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;static (inside,outside) aaa.bbb.ccc.108 exchange netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;static (inside,outside) aaa.bbb.ccc.105 exchange netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;static (inside,outside) aaa.bbb.ccc.106 citrix netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;static (inside,dmz) aaa.bbb.ccc.106 citrix netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;access-group inside_access_in in interface inside&lt;/P&gt;&lt;P&gt;access-group dmz_access_in in interface dmz&lt;/P&gt;&lt;P&gt;access-group DRSite_access_in in interface DRSite&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 aaa.bbb.ccc.1 1&lt;/P&gt;&lt;P&gt;route inside 10.0.0.0 255.0.0.0 10.255.0.1 1&lt;/P&gt;&lt;P&gt;route DRSite 192.168.0.0 255.255.0.0 192.168.0.1 1&lt;/P&gt;&lt;P&gt;ntp server 192.5.41.40 source outside prefer&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 09:07:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-pix-for-a-new-interface/m-p/516077#M498398</guid>
      <dc:creator>rcripe</dc:creator>
      <dc:date>2020-02-21T09:07:03Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring PIX for a new interface</title>
      <link>https://community.cisco.com/t5/network-security/configuring-pix-for-a-new-interface/m-p/516078#M498399</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,dmz) 10.0.0.0 10.0.0.0 netmask 255.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,dmz) 192.168.0.0 192.168.0.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH pls rate!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Aug 2006 17:56:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-pix-for-a-new-interface/m-p/516078#M498399</guid>
      <dc:creator>mmorris11</dc:creator>
      <dc:date>2006-08-17T17:56:54Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring PIX for a new interface</title>
      <link>https://community.cisco.com/t5/network-security/configuring-pix-for-a-new-interface/m-p/516079#M498400</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No luck.  I still can't ping from one side to the other.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's my show route display now:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FIREWALL# show route&lt;/P&gt;&lt;P&gt;        outside 0.0.0.0 0.0.0.0 aaa.bbb.ccc.1 1 OTHER static&lt;/P&gt;&lt;P&gt;        inside 10.0.0.0 255.0.0.0 10.255.0.1 1 OTHER static&lt;/P&gt;&lt;P&gt;        inside 10.255.0.0 255.255.255.0 10.255.0.254 1 CONNECT static&lt;/P&gt;&lt;P&gt;        dmz 38.112.5.136 255.255.255.252 38.112.5.138 1 CONNECT static&lt;/P&gt;&lt;P&gt;        DRSite 192.168.0.0 255.255.255.0 192.168.0.1 1 CONNECT static&lt;/P&gt;&lt;P&gt;        DRSite 192.168.0.0 255.255.0.0 192.168.0.1 1 OTHER static&lt;/P&gt;&lt;P&gt;        outside aaa.bbb.ccc.0 255.255.255.0 aaa.bbb.ccc.2 1 CONNECT static&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Aug 2006 18:23:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-pix-for-a-new-interface/m-p/516079#M498400</guid>
      <dc:creator>rcripe</dc:creator>
      <dc:date>2006-08-17T18:23:30Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring PIX for a new interface</title>
      <link>https://community.cisco.com/t5/network-security/configuring-pix-for-a-new-interface/m-p/516080#M498401</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My bad..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,DRSite) 10.0.0.0 10.0.0.0 netmask 255.0.0.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,DRSite) 192.168.0.0 192.168.0.0 netmask 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Aug 2006 18:50:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-pix-for-a-new-interface/m-p/516080#M498401</guid>
      <dc:creator>mmorris11</dc:creator>
      <dc:date>2006-08-17T18:50:08Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring PIX for a new interface</title>
      <link>https://community.cisco.com/t5/network-security/configuring-pix-for-a-new-interface/m-p/516081#M498402</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ah, yeah, I should have noticed that too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, it still doesn't work.  The second line conflicted with the global setting &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (DRSite) 1 192.168.0.2-192.168.0.200 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I tried it with the global setting and it didn't work.  Then I removed the global setting and used the static you indicated and tried again.  Still no luck.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Aug 2006 19:52:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-pix-for-a-new-interface/m-p/516081#M498402</guid>
      <dc:creator>rcripe</dc:creator>
      <dc:date>2006-08-17T19:52:52Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring PIX for a new interface</title>
      <link>https://community.cisco.com/t5/network-security/configuring-pix-for-a-new-interface/m-p/516082#M498403</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;try after doing a clear xlate.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Aug 2006 19:57:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-pix-for-a-new-interface/m-p/516082#M498403</guid>
      <dc:creator>mmorris11</dc:creator>
      <dc:date>2006-08-17T19:57:22Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring PIX for a new interface</title>
      <link>https://community.cisco.com/t5/network-security/configuring-pix-for-a-new-interface/m-p/516083#M498404</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you routing 10.255.0.x/24 properly such that the 192.168.0.x hosts will send the traffic to the pix for that subnet?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Run this debug while pinging  from the DR box:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug packet DRSite&lt;/P&gt;&lt;P&gt;term mon&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and see if you see the pings hitting the pix.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Aug 2006 20:01:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-pix-for-a-new-interface/m-p/516083#M498404</guid>
      <dc:creator>mmorris11</dc:creator>
      <dc:date>2006-08-17T20:01:34Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring PIX for a new interface</title>
      <link>https://community.cisco.com/t5/network-security/configuring-pix-for-a-new-interface/m-p/516084#M498405</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The PIX config looks good. Can you make sure the router or layer 3 switch connected to the inside network is forwarding the traffic to 192.168.0.0/24 subnet to the PIX and the devices/hosts on the DR subnet are using 192.168.0.1 as the gateway to get to your inside network. While you have been focusing your troubleshooting on PIX all this time it could be something as simple as a incorrect subnet mask setting on the host or might be a routing issue. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another thing you could try is if you have a router hanging off of the PIX interfaces, enable 'debug ip icmp' on it to see if echo and echo-replies are being received and sent. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good Luck!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sundar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Aug 2006 22:46:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-pix-for-a-new-interface/m-p/516084#M498405</guid>
      <dc:creator>sundar.palaniappan</dc:creator>
      <dc:date>2006-08-17T22:46:52Z</dc:date>
    </item>
  </channel>
</rss>

