<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help with routing on PIX 501 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/help-with-routing-on-pix-501/m-p/462461#M531350</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is DNS working properly so that you are able to ping a server on the 1.x net from the 10.x net by name?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 28 Oct 2005 01:36:02 GMT</pubDate>
    <dc:creator>bobd</dc:creator>
    <dc:date>2005-10-28T01:36:02Z</dc:date>
    <item>
      <title>Help with routing on PIX 501</title>
      <link>https://community.cisco.com/t5/network-security/help-with-routing-on-pix-501/m-p/462458#M531347</link>
      <description>&lt;P&gt;Hi everyone.&lt;/P&gt;&lt;P&gt;I generally do NOT do networking, so I may be a bit slow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to connect a branch office to a head office with two PIX 501s.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll need ping, traceroute and all windows packets to traverse the system.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The system topology is as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;head office (192.168.1.x) -&amp;gt; PIX501 (inside 192.168.1.247, outside X.X.X.X) -&amp;gt; &amp;lt;cloud&amp;gt; -&amp;gt; PIX501 (inside 192.168.10.247, outside x.x.x.x) -&amp;gt; branch office (192.168.10.x)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can establish both an IKE and IPSEC tunnel with my current configs, but I know I must be missing some essential route commands because I can't ping from the .10.x subnet to the .1.x subnet nor vice-versa.&lt;/P&gt;&lt;P&gt;I also have no windows servers (in the .1.x subnet) visible from the .10.x subnet either.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be appreciated.&lt;/P&gt;&lt;P&gt;I've attached the current configs for both units.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:29:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-with-routing-on-pix-501/m-p/462458#M531347</guid>
      <dc:creator>rickberes</dc:creator>
      <dc:date>2020-02-21T08:29:27Z</dc:date>
    </item>
    <item>
      <title>Re: Help with routing on PIX 501</title>
      <link>https://community.cisco.com/t5/network-security/help-with-routing-on-pix-501/m-p/462459#M531348</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your configs look fine for the tunnel from what I can see.  I assume the workstation that your trying to ping doesn't have problems or a software firewall preventing it from replying (XP sp2).  If you had built the configs and tried immediately, its possible that the IP address you were trying to ping from/to already had NAT entries on the PIX.  You would use CLEAR XLA on both firewalls to clear any existing translations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Oct 2005 16:58:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-with-routing-on-pix-501/m-p/462459#M531348</guid>
      <dc:creator>bobd</dc:creator>
      <dc:date>2005-10-27T16:58:09Z</dc:date>
    </item>
    <item>
      <title>Re: Help with routing on PIX 501</title>
      <link>https://community.cisco.com/t5/network-security/help-with-routing-on-pix-501/m-p/462460#M531349</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reponse Bob,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I CLEAR XLA'd both units and checked that my .1.x gateway was routing the .10.x traffic to the PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As it turned out, it was not - so I corrected the route info in my .1.x subnet and I can now ping from the .1.x subnet to the .10.x subnet and vice-versa.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm pretty happy about that, but I still have no windows server access, and it does not appear that netbios traffic is coming back to the .10.x subnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any other ideas? (your first ones were great, thanks)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Oct 2005 17:19:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-with-routing-on-pix-501/m-p/462460#M531349</guid>
      <dc:creator>rickberes</dc:creator>
      <dc:date>2005-10-27T17:19:38Z</dc:date>
    </item>
    <item>
      <title>Re: Help with routing on PIX 501</title>
      <link>https://community.cisco.com/t5/network-security/help-with-routing-on-pix-501/m-p/462461#M531350</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is DNS working properly so that you are able to ping a server on the 1.x net from the 10.x net by name?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Oct 2005 01:36:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-with-routing-on-pix-501/m-p/462461#M531350</guid>
      <dc:creator>bobd</dc:creator>
      <dc:date>2005-10-28T01:36:02Z</dc:date>
    </item>
    <item>
      <title>Re: Help with routing on PIX 501</title>
      <link>https://community.cisco.com/t5/network-security/help-with-routing-on-pix-501/m-p/462462#M531353</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the type of vpn do not match.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;on head office pix, you configure dynamic vpn acting as a server; whereas on the branch office pix, you configure lan-lan vpn as well as dynamic vpn acting as a server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;have a look at this doc for lan-lan vpn:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a0080094761.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a0080094761.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;have a look at this doc for ezvpn:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a008019e6d7.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a008019e6d7.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the main difference between the lan-lan vpn and ezvpn is that with lan-lan vpn, either sites are able to establish the vpn; whereas with ezvpn, only the client site can establish the vpn. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in order to determine which vpn to be deployed, you need to figure out the type of public ip on both sites. assuming both sites have static public ip, then you can choose either lan-lan vpn or ezvpn; whereas if only one of the sites has static public ip, then only ezvpn is feasible.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Oct 2005 02:35:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-with-routing-on-pix-501/m-p/462462#M531353</guid>
      <dc:creator>jackko</dc:creator>
      <dc:date>2005-10-28T02:35:29Z</dc:date>
    </item>
    <item>
      <title>Re: Help with routing on PIX 501</title>
      <link>https://community.cisco.com/t5/network-security/help-with-routing-on-pix-501/m-p/462463#M531357</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bob, thanks again.&lt;/P&gt;&lt;P&gt;Yes, I can ping by name and traceroute to servers by name.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I *think* I have full network functionality except I seem to be having problems joining the domain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a specific packet type I have to enable in order for this to work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry for the newbie questions, but like I said, I don't usually config this equipment. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 29 Oct 2005 17:47:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-with-routing-on-pix-501/m-p/462463#M531357</guid>
      <dc:creator>rickberes</dc:creator>
      <dc:date>2005-10-29T17:47:26Z</dc:date>
    </item>
    <item>
      <title>Re: Help with routing on PIX 501</title>
      <link>https://community.cisco.com/t5/network-security/help-with-routing-on-pix-501/m-p/462464#M531358</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If everything is there except for joining the domain it could just be a simple WINS problem.  Might be worth double checking WINS settings on your remote network workstations to be sure they are pointing to the WINS server on the main network.  LMHOSTS files can be used instead of WINS, but I don't usually go that route for a variety of reasons.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 29 Oct 2005 19:24:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-with-routing-on-pix-501/m-p/462464#M531358</guid>
      <dc:creator>bobd</dc:creator>
      <dc:date>2005-10-29T19:24:22Z</dc:date>
    </item>
  </channel>
</rss>

