<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX 515 - Multiple Subnets in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-515-multiple-subnets/m-p/462205#M535488</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you please list the commands to this post that one would use to add a second subnet to their PIX? I have searched and searched and have not been able to come up with that information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 18 Jul 2005 20:30:35 GMT</pubDate>
    <dc:creator>comoms_dot_com</dc:creator>
    <dc:date>2005-07-18T20:30:35Z</dc:date>
    <item>
      <title>PIX 515 - Multiple Subnets</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-multiple-subnets/m-p/462203#M535486</link>
      <description>&lt;P&gt;Can I have a /28 and a /24 both allocated into one PIX 515e? My current configuration is setup for the /28 and I would like to keep that address space just as it is and then add the /24 if possbile.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:16:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-multiple-subnets/m-p/462203#M535486</guid>
      <dc:creator>comoms_dot_com</dc:creator>
      <dc:date>2020-02-21T08:16:00Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515 - Multiple Subnets</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-multiple-subnets/m-p/462204#M535487</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, you can add /24 along.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jul 2005 17:57:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-multiple-subnets/m-p/462204#M535487</guid>
      <dc:creator>umedryk</dc:creator>
      <dc:date>2005-07-18T17:57:30Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515 - Multiple Subnets</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-multiple-subnets/m-p/462205#M535488</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you please list the commands to this post that one would use to add a second subnet to their PIX? I have searched and searched and have not been able to come up with that information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jul 2005 20:30:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-multiple-subnets/m-p/462205#M535488</guid>
      <dc:creator>comoms_dot_com</dc:creator>
      <dc:date>2005-07-18T20:30:35Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515 - Multiple Subnets</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-multiple-subnets/m-p/462206#M535489</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"Can I have a /28 and a /24 both allocated into one PIX 515e?", do u mean a secondary ip on the same interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if yes, then i believe it's not feasible.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jul 2005 21:10:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-multiple-subnets/m-p/462206#M535489</guid>
      <dc:creator>jackko</dc:creator>
      <dc:date>2005-07-18T21:10:18Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515 - Multiple Subnets</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-multiple-subnets/m-p/462207#M535490</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"do u mean a secondary ip on the same interface?"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I currently have a /28 setup in my PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The outside interface is xx.185.xxx.xxx &lt;/P&gt;&lt;P&gt;The inside interface is 192.168.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am using NAT to translate my public addresses from the outside to the inside. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have run out of addresses in my /28 so I requested a /24 and have just recieved them from my provider. Being that I have been using this /28 for some time and I am in full production I do not want to get rid of those addresses and they are not somewhere in the range of addresses in my /24. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I am hoping to be able to do is to add this second subnet to my PIX and translate both subnets to my inside addresses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can this be done?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for all of your help!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jul 2005 22:04:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-multiple-subnets/m-p/462207#M535490</guid>
      <dc:creator>comoms_dot_com</dc:creator>
      <dc:date>2005-07-18T22:04:51Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515 - Multiple Subnets</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-multiple-subnets/m-p/462208#M535491</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;assuming the pix interface is not capable for a secondary ip.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;an alternative would be to implement a router before or after the pix performing NAT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;another alternative is to use dynamic dns such as dyndns.org&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jul 2005 23:57:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-multiple-subnets/m-p/462208#M535491</guid>
      <dc:creator>jackko</dc:creator>
      <dc:date>2005-07-18T23:57:26Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515 - Multiple Subnets</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-multiple-subnets/m-p/462209#M535492</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you can configure PIX interface as trunk. Now you can assign multible address for the same interface like your conventional 802.1q trunking. This feature supported only above version 6.3. You can ref. below faq.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/partner/products/hw/vpndevc/ps2030/products_qanda_item09186a0080094874.shtml" target="_blank"&gt;http://www.cisco.com/en/US/partner/products/hw/vpndevc/ps2030/products_qanda_item09186a0080094874.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VMSundaram&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jul 2005 08:18:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-multiple-subnets/m-p/462209#M535492</guid>
      <dc:creator>meenakshi</dc:creator>
      <dc:date>2005-07-19T08:18:05Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515 - Multiple Subnets</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-multiple-subnets/m-p/462210#M535493</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can not login with my username and password to that link.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jul 2005 20:01:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-multiple-subnets/m-p/462210#M535493</guid>
      <dc:creator>comoms_dot_com</dc:creator>
      <dc:date>2005-07-19T20:01:53Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515 - Multiple Subnets</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-multiple-subnets/m-p/462211#M535494</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for the info meenakshi!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;according to the doco:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Step 1 Assign the interface speed to a physical interface by entering the following command:&lt;/P&gt;&lt;P&gt;interface ethernet0 auto&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Step 2 Assign VLAN2 to the physical interface (ethernet0) by entering the following command:&lt;/P&gt;&lt;P&gt;interface ethernet0 vlan2 physical&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By assigning a VLAN to the physical interface, you ensure that all frames forwarded on the interface will be tagged. VLAN 1 is not used because that is the default native VLAN for Cisco switches. Without the physical parameter, the default for the interface command is to create a logical interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Step 3 Create a new logical interface (VLAN3) and tie it to the physical interface (ethernet0) by entering the following command:&lt;/P&gt;&lt;P&gt;interface ethernet0 vlan3 logical&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will allow the PIX Firewall to send and receive VLAN-tagged packets with a VLAN identifier equal to 3 on the physical interface, ethernet0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Step 4 Configure the logical and physical interfaces by entering the following commands:&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;nameif vlan3 dmz security50&lt;/P&gt;&lt;P&gt;ipaddress outside 192.168.101.1 255.255.255.0&lt;/P&gt;&lt;P&gt;ipaddress dmz 192.168.103.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jul 2005 22:46:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-multiple-subnets/m-p/462211#M535494</guid>
      <dc:creator>jackko</dc:creator>
      <dc:date>2005-07-19T22:46:08Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515 - Multiple Subnets</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-multiple-subnets/m-p/462212#M535495</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;tested the code after posting it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it seems like the feature works with vlan only, that means it cannot be used as a stand-alone logical interface. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thus it doesn't help with the posted scenario, unless you setup a vlan outside the pix which may not be feasible&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jul 2005 23:42:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-multiple-subnets/m-p/462212#M535495</guid>
      <dc:creator>jackko</dc:creator>
      <dc:date>2005-07-19T23:42:57Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515 - Multiple Subnets</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-multiple-subnets/m-p/462213#M535496</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi VMSundaram,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But how can insert a failover pix in this senario using only a single L2 switch with 802.1q trunk to primary pix and failover pix?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Aug 2005 06:25:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-multiple-subnets/m-p/462213#M535496</guid>
      <dc:creator>wanghmk1223</dc:creator>
      <dc:date>2005-08-05T06:25:12Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515 - Multiple Subnets</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-multiple-subnets/m-p/462214#M535497</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I think the solution is more simple than you think. You can use your new address-range with nat, global and statics without actually configure it on the physical interface. That way you can use your new address-space. Your ISP have to route your new network to your PIX outside interface. That is all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;Robert Maras&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Aug 2005 06:37:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-multiple-subnets/m-p/462214#M535497</guid>
      <dc:creator>maraz</dc:creator>
      <dc:date>2005-08-05T06:37:41Z</dc:date>
    </item>
  </channel>
</rss>

