<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Pix multiple internet access in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-multiple-internet-access/m-p/589660#M502210</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;try this link &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_quick_start09186a00805f725c.html" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_quick_start09186a00805f725c.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 27 Apr 2006 13:15:08 GMT</pubDate>
    <dc:creator>beth-martin</dc:creator>
    <dc:date>2006-04-27T13:15:08Z</dc:date>
    <item>
      <title>Pix multiple internet access</title>
      <link>https://community.cisco.com/t5/network-security/pix-multiple-internet-access/m-p/589659#M502209</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's my hardware layout:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've got a Pix 515E UR w/ 6 ports @ ver7.1(2)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've got two T1 connections to the internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently I've got the following interfaces: inside(sec level 100), outside(sec 0)(1st T1), dmz(sec 50) and T1(sec 0)(2nd T1).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The inside interface only needs access to dmz and T1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The DMZ has an email server and I would need to restrict it to only using the outside interface to access the internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've tried to do this in single context mode with no luck keeping the dmz from just access the outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's my question: Is this possible in single context and I'm just missing something or should I go to multiple contexts?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:51:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-multiple-internet-access/m-p/589659#M502209</guid>
      <dc:creator>qvoyles</dc:creator>
      <dc:date>2020-02-21T08:51:08Z</dc:date>
    </item>
    <item>
      <title>Re: Pix multiple internet access</title>
      <link>https://community.cisco.com/t5/network-security/pix-multiple-internet-access/m-p/589660#M502210</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;try this link &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_quick_start09186a00805f725c.html" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_quick_start09186a00805f725c.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Apr 2006 13:15:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-multiple-internet-access/m-p/589660#M502210</guid>
      <dc:creator>beth-martin</dc:creator>
      <dc:date>2006-04-27T13:15:08Z</dc:date>
    </item>
    <item>
      <title>Re: Pix multiple internet access</title>
      <link>https://community.cisco.com/t5/network-security/pix-multiple-internet-access/m-p/589661#M502211</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Why don't you try a "trick"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Create PAT for devices on the inside network going towards DMZ and T1 ie.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 1 &lt;INSIDE hosts=""&gt;&lt;/INSIDE&gt;&lt;/P&gt;&lt;P&gt;global (dmz) 1 &lt;ROUTABLE dmz="" ip="" address=""&gt;&lt;/ROUTABLE&gt;&lt;/P&gt;&lt;P&gt;global (T1) 1 &lt;ROUTABLE ip="" address=""&gt;&lt;/ROUTABLE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Restrict access from inside host to the outside interface by doing PAT using a facke NONROUTABLE address &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 1 &lt;INSIDE hosts=""&gt;&lt;/INSIDE&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 &lt;NON-ROUTABLE ip="" address=""&gt;&lt;/NON-ROUTABLE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As the NATes IP will be nonroutable on the outside interface ..  the traffic will fall on a black hole &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Post it if you find it helps&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Apr 2006 23:24:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-multiple-internet-access/m-p/589661#M502211</guid>
      <dc:creator>Fernando_Meza</dc:creator>
      <dc:date>2006-04-27T23:24:09Z</dc:date>
    </item>
  </channel>
</rss>

