<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: pix with two different network in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-with-two-different-network/m-p/439402#M533787</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;first of all, i had miss type at last reply please correct it : global (outside2) 2 interface &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in fact there isn't any facilities to implement source routing at pix software except version 7.x that i'm not sure, in order to specify the route that a packet should take through the network (for two default gateways from two ISPs) so if you have perimeter router at your network that is connected to ISPs we can implement your situation as below :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;LAN---PIX---Router--{two connections ISP1 ISP2}&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX : &lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip address outside 192.168.100.1 255.255.255.252&lt;/P&gt;&lt;P&gt;ip address inside 172.16.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 1 172.16.1.0 255.255.255.128&lt;/P&gt;&lt;P&gt;nat (inside) 2 172.16.1.128 255.255.255.128&lt;/P&gt;&lt;P&gt;global (outside) 1 100.100.100.10 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;global (outside2) 2 200.200.200.20 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 192.168.100.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Router :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface FastEthernet0/0&lt;/P&gt;&lt;P&gt;description connected to PIX&lt;/P&gt;&lt;P&gt;ip address 192.168.100.2 255.255.255.252&lt;/P&gt;&lt;P&gt;ip policy route-map providers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 130 permit ip host 100.100.100.10 any&lt;/P&gt;&lt;P&gt;access-list 131 permit ip host 200.200.200.20 any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route-map providers permit 130&lt;/P&gt;&lt;P&gt;match ip address 130&lt;/P&gt;&lt;P&gt;set ip next-hop ISP1 &lt;/P&gt;&lt;P&gt;route-map providers permit 131&lt;/P&gt;&lt;P&gt;match ip address 131&lt;/P&gt;&lt;P&gt;set ip next-hop ISP2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip router 100.100.100.10 255.255.255.255 192.168.100.1&lt;/P&gt;&lt;P&gt;ip router 200.200.200.20 255.255.255.255 192.168.100.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this scenario half of your network go through one ISP (send/receive from same ISP) and rest of the network from another ISP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hope this help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Mehrdad Arshad Rad&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 04 Sep 2005 08:07:29 GMT</pubDate>
    <dc:creator>mehrdad</dc:creator>
    <dc:date>2005-09-04T08:07:29Z</dc:date>
    <item>
      <title>pix with two different network</title>
      <link>https://community.cisco.com/t5/network-security/pix-with-two-different-network/m-p/439397#M533778</link>
      <description>&lt;P&gt;i am new in pix, i need to know is it possiable to configure PIX with complitely two different network IP.&lt;/P&gt;&lt;P&gt;exp. i have two internet connection have IP 100.100.100.10 and 200.200.200.20&lt;/P&gt;&lt;P&gt;my local network user IP network is 172.16.1.0. Pls give me a clue.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:21:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-with-two-different-network/m-p/439397#M533778</guid>
      <dc:creator>khandakartuhin</dc:creator>
      <dc:date>2020-02-21T08:21:33Z</dc:date>
    </item>
    <item>
      <title>Re: pix with two different network</title>
      <link>https://community.cisco.com/t5/network-security/pix-with-two-different-network/m-p/439398#M533780</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you can't define secondary address to an interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Aug 2005 14:13:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-with-two-different-network/m-p/439398#M533780</guid>
      <dc:creator>mehrdad</dc:creator>
      <dc:date>2005-08-30T14:13:07Z</dc:date>
    </item>
    <item>
      <title>Re: pix with two different network</title>
      <link>https://community.cisco.com/t5/network-security/pix-with-two-different-network/m-p/439399#M533782</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You should connect each provider to specify zone then use them, unfortunately there isn't any load balance at the PIX so you should balance your inside internet usage traffic through NAT, it means NAT half of your network through provider1 and rest of network by provider2&lt;/P&gt;&lt;P&gt;for example :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;nameif ethernet2 outside2 security5&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip address outside 100.100.100.10 255.255.255.0&lt;/P&gt;&lt;P&gt;ip address outside2 200.200.200.20 255.255.255.0&lt;/P&gt;&lt;P&gt;ip address inside 172.16.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 1 172.16.1.0 255.255.255.128&lt;/P&gt;&lt;P&gt;nat (inside) 2 172.16.1.128 255.255.255.128&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;global (outside2) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Mehrdad&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Aug 2005 15:02:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-with-two-different-network/m-p/439399#M533782</guid>
      <dc:creator>mehrdad</dc:creator>
      <dc:date>2005-08-30T15:02:47Z</dc:date>
    </item>
    <item>
      <title>Re: pix with two different network</title>
      <link>https://community.cisco.com/t5/network-security/pix-with-two-different-network/m-p/439400#M533784</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When you say you have two Internet connections, do you mean:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.  You have two separate network connections with one IP address each or;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.  You have one network connection with two IP addresses?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Each situation has a different solution.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Solution 1:  If you have two separate network connections with one IP address each, you most likey have a Pix 515 or above.  Just assign each interface its own IP:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip address outside 100.100.100.10 255.255.255.0&lt;/P&gt;&lt;P&gt;ip address inside 172.16.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt;ip address dmz 200.200.200.20 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Solution 2:  If you have one network connection with two IP addresses, you set the first address to the outside interface and create a static translation for the second address:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip address outside 100.100.100.10 255.255.255.0&lt;/P&gt;&lt;P&gt;ip address inside 172.16.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt;static (inside,outside) 200.200.200.20 172.16.1.20 netmask 255.255.255.0 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know if this information helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Aug 2005 16:15:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-with-two-different-network/m-p/439400#M533784</guid>
      <dc:creator>pwicks</dc:creator>
      <dc:date>2005-08-30T16:15:08Z</dc:date>
    </item>
    <item>
      <title>Re: pix with two different network</title>
      <link>https://community.cisco.com/t5/network-security/pix-with-two-different-network/m-p/439401#M533785</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is there any problem broadcust, multicust or igmp problem from one outside network to other outside network? i dont want any packet come and go from one outside to other outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 04 Sep 2005 03:20:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-with-two-different-network/m-p/439401#M533785</guid>
      <dc:creator>khandakartuhin</dc:creator>
      <dc:date>2005-09-04T03:20:01Z</dc:date>
    </item>
    <item>
      <title>Re: pix with two different network</title>
      <link>https://community.cisco.com/t5/network-security/pix-with-two-different-network/m-p/439402#M533787</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;first of all, i had miss type at last reply please correct it : global (outside2) 2 interface &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in fact there isn't any facilities to implement source routing at pix software except version 7.x that i'm not sure, in order to specify the route that a packet should take through the network (for two default gateways from two ISPs) so if you have perimeter router at your network that is connected to ISPs we can implement your situation as below :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;LAN---PIX---Router--{two connections ISP1 ISP2}&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX : &lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip address outside 192.168.100.1 255.255.255.252&lt;/P&gt;&lt;P&gt;ip address inside 172.16.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 1 172.16.1.0 255.255.255.128&lt;/P&gt;&lt;P&gt;nat (inside) 2 172.16.1.128 255.255.255.128&lt;/P&gt;&lt;P&gt;global (outside) 1 100.100.100.10 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;global (outside2) 2 200.200.200.20 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 192.168.100.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Router :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface FastEthernet0/0&lt;/P&gt;&lt;P&gt;description connected to PIX&lt;/P&gt;&lt;P&gt;ip address 192.168.100.2 255.255.255.252&lt;/P&gt;&lt;P&gt;ip policy route-map providers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 130 permit ip host 100.100.100.10 any&lt;/P&gt;&lt;P&gt;access-list 131 permit ip host 200.200.200.20 any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route-map providers permit 130&lt;/P&gt;&lt;P&gt;match ip address 130&lt;/P&gt;&lt;P&gt;set ip next-hop ISP1 &lt;/P&gt;&lt;P&gt;route-map providers permit 131&lt;/P&gt;&lt;P&gt;match ip address 131&lt;/P&gt;&lt;P&gt;set ip next-hop ISP2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip router 100.100.100.10 255.255.255.255 192.168.100.1&lt;/P&gt;&lt;P&gt;ip router 200.200.200.20 255.255.255.255 192.168.100.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this scenario half of your network go through one ISP (send/receive from same ISP) and rest of the network from another ISP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hope this help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Mehrdad Arshad Rad&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 04 Sep 2005 08:07:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-with-two-different-network/m-p/439402#M533787</guid>
      <dc:creator>mehrdad</dc:creator>
      <dc:date>2005-09-04T08:07:29Z</dc:date>
    </item>
    <item>
      <title>Re: pix with two different network</title>
      <link>https://community.cisco.com/t5/network-security/pix-with-two-different-network/m-p/439403#M533789</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks to all for ur soluation,&lt;/P&gt;&lt;P&gt;actually i am not clear of my quistion, sorry for that.&lt;/P&gt;&lt;P&gt;what i really want,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;two different internet configured in one pix firewall. (four eth port)&lt;/P&gt;&lt;P&gt;all local user have no access to internet. i don't need any DMZ.&lt;/P&gt;&lt;P&gt;only three static entry is mail, www and proxy.&lt;/P&gt;&lt;P&gt;users only access to this three server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Both internet must not communicate or send any packet to each other"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, Possiable?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Sep 2005 11:46:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-with-two-different-network/m-p/439403#M533789</guid>
      <dc:creator>khandakartuhin</dc:creator>
      <dc:date>2005-09-05T11:46:44Z</dc:date>
    </item>
    <item>
      <title>Re: pix with two different network</title>
      <link>https://community.cisco.com/t5/network-security/pix-with-two-different-network/m-p/439404#M533790</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, Just curious.. Is there a posibility if we connected to two ISPs, an auto failover can be done if you have configured a static load balance?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Sep 2005 04:32:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-with-two-different-network/m-p/439404#M533790</guid>
      <dc:creator>blyap20</dc:creator>
      <dc:date>2005-09-07T04:32:25Z</dc:date>
    </item>
    <item>
      <title>Re: pix with two different network</title>
      <link>https://community.cisco.com/t5/network-security/pix-with-two-different-network/m-p/439405#M533791</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks to all for ur soluation, &lt;/P&gt;&lt;P&gt;actually i am not clear of my quistion, sorry for that. &lt;/P&gt;&lt;P&gt;what i really want, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;two different internet configured in one pix firewall. (four eth port) &lt;/P&gt;&lt;P&gt;all local user have no access to internet. i don't need any DMZ. &lt;/P&gt;&lt;P&gt;only three static entry is mail, www and proxy. &lt;/P&gt;&lt;P&gt;users only access to this three server. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Both internet must not communicate or send any packet to each other" &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, Possiable? &lt;/P&gt;&lt;P&gt;And Do anybody know how to start a new conversation....?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Sep 2005 10:45:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-with-two-different-network/m-p/439405#M533791</guid>
      <dc:creator>khandakartuhin</dc:creator>
      <dc:date>2005-09-07T10:45:11Z</dc:date>
    </item>
    <item>
      <title>Re: pix with two different network</title>
      <link>https://community.cisco.com/t5/network-security/pix-with-two-different-network/m-p/439406#M533792</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks to all for ur soluation, &lt;/P&gt;&lt;P&gt;actually i am not clear of my quistion, sorry for that. &lt;/P&gt;&lt;P&gt;what i really want, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;two different internet configured in one pix firewall. (four eth port) &lt;/P&gt;&lt;P&gt;all local user have no access to internet. i don't need any DMZ. &lt;/P&gt;&lt;P&gt;only three static entry is mail, www and proxy. &lt;/P&gt;&lt;P&gt;users only access to this three server. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Both internet must not communicate or send any packet to each other" &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, Possiable with VLAN?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And Do anybody know how to start a new conversation....?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Sep 2005 11:08:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-with-two-different-network/m-p/439406#M533792</guid>
      <dc:creator>khandakartuhin</dc:creator>
      <dc:date>2005-09-07T11:08:39Z</dc:date>
    </item>
  </channel>
</rss>

