<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can a PIX 515e support more than one subnet? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-a-pix-515e-support-more-than-one-subnet/m-p/489666#M535180</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I do not have a router. My provider assigns me a subnet and I have a PIX as the front line to the internet. I use the PIX to do NAT to my webserver. The /28 that was originally assigned was enough to handle me for the last few years. Now, I need to have all of my sites have an SSL certificate so I need more IPs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The /24 that was assigned has the addresses of:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Range:  207.7.109.0/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Default Gateway:  207.7.109.1&lt;/P&gt;&lt;P&gt;Usable:  207.7.109.2 - 207.7.109.254&lt;/P&gt;&lt;P&gt;Subnet Mask:  255.255.255.0&lt;/P&gt;&lt;P&gt;[Network:  207.7.109.0; Broadcast:  207.7.109.255]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The /28 is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Range:  66.185.162.160/28&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Default Gateway: 66.185.162.161&lt;/P&gt;&lt;P&gt;Usable:  66.185.162.162 - 66.185.162.174&lt;/P&gt;&lt;P&gt;Subnet Mask:  255.255.255.240&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Network: 66.185.162.160 ; Broadcast: 66.185.162.175 ]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to add this /24 along side my /28 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have attached my config for review.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 19 Jul 2005 21:10:16 GMT</pubDate>
    <dc:creator>comoms_dot_com</dc:creator>
    <dc:date>2005-07-19T21:10:16Z</dc:date>
    <item>
      <title>Can a PIX 515e support more than one subnet?</title>
      <link>https://community.cisco.com/t5/network-security/can-a-pix-515e-support-more-than-one-subnet/m-p/489662#M535167</link>
      <description>&lt;P&gt;I currently have a /28 setup in my PIX. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The outside interface is xx.185.xxx.xxx &lt;/P&gt;&lt;P&gt;The inside interface is 192.168.1.1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am using NAT to translate my public addresses from the outside to the inside. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have run out of addresses in my /28 so I requested a /24 and have just recieved them from my provider. Being that I have been using this /28 for some time and I am in full production I do not want to get rid of those addresses and they are not somewhere in the range of addresses in my /24. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I am hoping to be able to do is to add this second subnet to my PIX and translate both subnets to my inside addresses. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can this be done? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for all of your help! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:16:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-a-pix-515e-support-more-than-one-subnet/m-p/489662#M535167</guid>
      <dc:creator>comoms_dot_com</dc:creator>
      <dc:date>2020-02-21T08:16:54Z</dc:date>
    </item>
    <item>
      <title>Re: Can a PIX 515e support more than one subnet?</title>
      <link>https://community.cisco.com/t5/network-security/can-a-pix-515e-support-more-than-one-subnet/m-p/489663#M535171</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, you can define more subnets or networks in your translation statements nat/global or static. As long as you have the correct routing setup to forward those IP addresses to PIX, PIX will pickup those packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Nadeem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jul 2005 19:58:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-a-pix-515e-support-more-than-one-subnet/m-p/489663#M535171</guid>
      <dc:creator>nkhawaja</dc:creator>
      <dc:date>2005-07-19T19:58:04Z</dc:date>
    </item>
    <item>
      <title>Re: Can a PIX 515e support more than one subnet?</title>
      <link>https://community.cisco.com/t5/network-security/can-a-pix-515e-support-more-than-one-subnet/m-p/489664#M535176</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So my provider will need to route the addresses to my first IP in the /28 range? I am pretty confused on how to make this happen.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jul 2005 20:04:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-a-pix-515e-support-more-than-one-subnet/m-p/489664#M535176</guid>
      <dc:creator>comoms_dot_com</dc:creator>
      <dc:date>2005-07-19T20:04:36Z</dc:date>
    </item>
    <item>
      <title>Re: Can a PIX 515e support more than one subnet?</title>
      <link>https://community.cisco.com/t5/network-security/can-a-pix-515e-support-more-than-one-subnet/m-p/489665#M535178</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;your provider will be routing both of these address spaces to your router. your router will then be routing these to the pix. pix will be picking up those packets based on the translation and access rules&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jul 2005 20:29:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-a-pix-515e-support-more-than-one-subnet/m-p/489665#M535178</guid>
      <dc:creator>nkhawaja</dc:creator>
      <dc:date>2005-07-19T20:29:22Z</dc:date>
    </item>
    <item>
      <title>Re: Can a PIX 515e support more than one subnet?</title>
      <link>https://community.cisco.com/t5/network-security/can-a-pix-515e-support-more-than-one-subnet/m-p/489666#M535180</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I do not have a router. My provider assigns me a subnet and I have a PIX as the front line to the internet. I use the PIX to do NAT to my webserver. The /28 that was originally assigned was enough to handle me for the last few years. Now, I need to have all of my sites have an SSL certificate so I need more IPs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The /24 that was assigned has the addresses of:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Range:  207.7.109.0/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Default Gateway:  207.7.109.1&lt;/P&gt;&lt;P&gt;Usable:  207.7.109.2 - 207.7.109.254&lt;/P&gt;&lt;P&gt;Subnet Mask:  255.255.255.0&lt;/P&gt;&lt;P&gt;[Network:  207.7.109.0; Broadcast:  207.7.109.255]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The /28 is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Range:  66.185.162.160/28&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Default Gateway: 66.185.162.161&lt;/P&gt;&lt;P&gt;Usable:  66.185.162.162 - 66.185.162.174&lt;/P&gt;&lt;P&gt;Subnet Mask:  255.255.255.240&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Network: 66.185.162.160 ; Broadcast: 66.185.162.175 ]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to add this /24 along side my /28 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have attached my config for review.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jul 2005 21:10:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-a-pix-515e-support-more-than-one-subnet/m-p/489666#M535180</guid>
      <dc:creator>comoms_dot_com</dc:creator>
      <dc:date>2005-07-19T21:10:16Z</dc:date>
    </item>
    <item>
      <title>Re: Can a PIX 515e support more than one subnet?</title>
      <link>https://community.cisco.com/t5/network-security/can-a-pix-515e-support-more-than-one-subnet/m-p/489667#M535182</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;in that case your ISP should route the other subnet as well to your PIX.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jul 2005 15:49:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-a-pix-515e-support-more-than-one-subnet/m-p/489667#M535182</guid>
      <dc:creator>nkhawaja</dc:creator>
      <dc:date>2005-07-20T15:49:32Z</dc:date>
    </item>
    <item>
      <title>Re: Can a PIX 515e support more than one subnet?</title>
      <link>https://community.cisco.com/t5/network-security/can-a-pix-515e-support-more-than-one-subnet/m-p/489668#M535183</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The problem lies in the fact that the two networks are completely separate and you cannot run two networks on the outside interface.  They have not extended his addressing but they allocated a new range, not very nice.  I would like to hear if anyone else has had this problem.  All I can see is you having to add in another  PIX.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Jul 2005 11:53:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-a-pix-515e-support-more-than-one-subnet/m-p/489668#M535183</guid>
      <dc:creator>groberton</dc:creator>
      <dc:date>2005-07-21T11:53:09Z</dc:date>
    </item>
  </channel>
</rss>

