<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PIX 515 : routing issue + NAT in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-515-routing-issue-nat/m-p/1318338#M502816</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a routing + NAT issue with my PIX 515 (v7.2.4).&lt;/P&gt;&lt;P&gt;Indeed, i can't reach at the same time, my outside interface (Internet) and a subnetwork in my inside network using a router which has an ip on my inside network.&lt;/P&gt;&lt;P&gt;here is my conf :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX Version 7.2(4) &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address Public_IP 255.255.255.248 &lt;/P&gt;&lt;P&gt; ospf cost 10&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet1&lt;/P&gt;&lt;P&gt; description Office LAN&lt;/P&gt;&lt;P&gt; speed 100&lt;/P&gt;&lt;P&gt; duplex full&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.10.10.254 255.255.255.0 &lt;/P&gt;&lt;P&gt; ospf cost 10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip verify reverse-path interface outside&lt;/P&gt;&lt;P&gt;ip verify reverse-path interface inside&lt;/P&gt;&lt;P&gt;ip verify reverse-path interface VoIP-inside&lt;/P&gt;&lt;P&gt;ip verify reverse-path interface DMZ&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;icmp deny any outside&lt;/P&gt;&lt;P&gt;icmp permit any inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (inside) 1 interface&lt;/P&gt;&lt;P&gt;nat (outside) 0 access-list outside_nat0_outbound&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list inside_nat0_outbound&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group inbound in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 203.XXX.XXX.XXX 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route inside 10.0.100.0 255.255.252.0 10.10.10.29 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Packet tracer show a NAT issue with the dynamic NAT policy but i don't know why.&lt;/P&gt;&lt;P&gt;When i remove the dynamic NAT policy, i can reach the subnetwork but no more internet...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Laurent&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 11:43:39 GMT</pubDate>
    <dc:creator>IT-Volubill</dc:creator>
    <dc:date>2020-02-21T11:43:39Z</dc:date>
    <item>
      <title>PIX 515 : routing issue + NAT</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-routing-issue-nat/m-p/1318338#M502816</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a routing + NAT issue with my PIX 515 (v7.2.4).&lt;/P&gt;&lt;P&gt;Indeed, i can't reach at the same time, my outside interface (Internet) and a subnetwork in my inside network using a router which has an ip on my inside network.&lt;/P&gt;&lt;P&gt;here is my conf :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX Version 7.2(4) &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address Public_IP 255.255.255.248 &lt;/P&gt;&lt;P&gt; ospf cost 10&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet1&lt;/P&gt;&lt;P&gt; description Office LAN&lt;/P&gt;&lt;P&gt; speed 100&lt;/P&gt;&lt;P&gt; duplex full&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.10.10.254 255.255.255.0 &lt;/P&gt;&lt;P&gt; ospf cost 10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip verify reverse-path interface outside&lt;/P&gt;&lt;P&gt;ip verify reverse-path interface inside&lt;/P&gt;&lt;P&gt;ip verify reverse-path interface VoIP-inside&lt;/P&gt;&lt;P&gt;ip verify reverse-path interface DMZ&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;icmp deny any outside&lt;/P&gt;&lt;P&gt;icmp permit any inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (inside) 1 interface&lt;/P&gt;&lt;P&gt;nat (outside) 0 access-list outside_nat0_outbound&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list inside_nat0_outbound&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group inbound in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 203.XXX.XXX.XXX 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route inside 10.0.100.0 255.255.252.0 10.10.10.29 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Packet tracer show a NAT issue with the dynamic NAT policy but i don't know why.&lt;/P&gt;&lt;P&gt;When i remove the dynamic NAT policy, i can reach the subnetwork but no more internet...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Laurent&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:43:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-routing-issue-nat/m-p/1318338#M502816</guid>
      <dc:creator>IT-Volubill</dc:creator>
      <dc:date>2020-02-21T11:43:39Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515 : routing issue + NAT</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-routing-issue-nat/m-p/1318339#M502820</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Laurent,&lt;/P&gt;&lt;P&gt;can you clarify in more detail what you are trying to achieve, maybe with an example using actual ip addresses?&lt;/P&gt;&lt;P&gt;Can you also include the packet-tracer output please.&lt;/P&gt;&lt;P&gt;tnx&lt;/P&gt;&lt;P&gt;Herbert&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Oct 2009 05:21:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-routing-issue-nat/m-p/1318339#M502820</guid>
      <dc:creator>Herbert Baerten</dc:creator>
      <dc:date>2009-10-13T05:21:45Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515 : routing issue + NAT</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-routing-issue-nat/m-p/1318340#M502823</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to be able to access at the same time Internet (outside interface) and a subnetwork in my inside interface.&lt;/P&gt;&lt;P&gt;Example :&lt;/P&gt;&lt;P&gt;Inside network : 10.10.10.0/24&lt;/P&gt;&lt;P&gt;PIX inside : 10.10.10.254&lt;/P&gt;&lt;P&gt;IP of my router in the inside network : 10.10.10.29&lt;/P&gt;&lt;P&gt;Subnetwork behind my router : 10.0.100.0/24&lt;/P&gt;&lt;P&gt;To access outside, i have a Dynamic NAT, but with this Dynamic NAT enable then i can't ping the subnetwork while i can ping google.com for example.&lt;/P&gt;&lt;P&gt;If i remove the Dynamic NAT, then i can ping the subnetwork but i can't no more reach Internet (ping google.com not working).&lt;/P&gt;&lt;P&gt;As i have ios v7.2.4, i follow this guide : &lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a0080734db7.shtml#t3" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a0080734db7.shtml#t3&lt;/A&gt; but enabling intra-interface communication is not sufficient.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Laurent&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Oct 2009 09:10:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-routing-issue-nat/m-p/1318340#M502823</guid>
      <dc:creator>IT-Volubill</dc:creator>
      <dc:date>2009-10-13T09:10:32Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515 : routing issue + NAT</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-routing-issue-nat/m-p/1318341#M502825</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;If its feasible, add a static route for reaching 10.0.100.0 pointing towards 10.10.10.29, on each system on the subnet 10.10.10.0.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Oct 2009 09:24:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-routing-issue-nat/m-p/1318341#M502825</guid>
      <dc:creator>dhananjoy chowdhury</dc:creator>
      <dc:date>2009-10-13T09:24:27Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515 : routing issue + NAT</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-routing-issue-nat/m-p/1318342#M502827</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, assuming you are pinging from 10.10.10.x, it would be easiest to simply use 10.10.10.29 as your default gw, so the inside-to-inside traffic does not pass the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, if it is a requirement for this traffic to pass the fw, then I would advise to consider moving one of the inside networks to another firewall interface (if your license allows it).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Otherwise, I guess you would need something like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no global (inside) 1 interface&lt;/P&gt;&lt;P&gt;global (inside) 2 interface&lt;/P&gt;&lt;P&gt;nat (inside) 2 0.0.0.0 0.0.0.0 outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If that does not help, could you please provide the packet-tracer output (from the CLI) ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Oct 2009 09:35:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-routing-issue-nat/m-p/1318342#M502827</guid>
      <dc:creator>Herbert Baerten</dc:creator>
      <dc:date>2009-10-13T09:35:18Z</dc:date>
    </item>
  </channel>
</rss>

