<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: static route on PIX in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/static-route-on-pix/m-p/315362#M550577</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have default route set to PIX IP address in both the hosts?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 13 Mar 2005 00:45:38 GMT</pubDate>
    <dc:creator>rais</dc:creator>
    <dc:date>2005-03-13T00:45:38Z</dc:date>
    <item>
      <title>static route on PIX</title>
      <link>https://community.cisco.com/t5/network-security/static-route-on-pix/m-p/315359#M550574</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've LAN 192.168.4.0/24 with PIX /192.168.4.1/ which users has set as gateway and with Cisco805 /192.168.4.100/. And I've LAN 192.168.1.0 with Cisco805 /192.168.1.100/. I need on PIX set static route for LAN 192.168.1.0 where gw will be set 192.168.4.100.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In Windows desktop in LAN 192.168.4.0 I use:&lt;/P&gt;&lt;P&gt;route add 192.168.1.0 mask 255.255.255.0 192.168.4.100, can I set something like this on the PIX?&lt;/P&gt;&lt;P&gt;Thanx, Milan&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:00:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-route-on-pix/m-p/315359#M550574</guid>
      <dc:creator>milan.zmarzlak</dc:creator>
      <dc:date>2020-02-21T08:00:29Z</dc:date>
    </item>
    <item>
      <title>Re: static route on PIX</title>
      <link>https://community.cisco.com/t5/network-security/static-route-on-pix/m-p/315360#M550575</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can use the following command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route inside 192.168.1.0 255.255.255.0 192.168.4.100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 12 Mar 2005 11:43:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-route-on-pix/m-p/315360#M550575</guid>
      <dc:creator>rais</dc:creator>
      <dc:date>2005-03-12T11:43:16Z</dc:date>
    </item>
    <item>
      <title>Re: static route on PIX</title>
      <link>https://community.cisco.com/t5/network-security/static-route-on-pix/m-p/315361#M550576</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I tried this, in this case I can ping from console on PIX to 192.168.1.100, but I can't ping from desktop in LAN 192.168.4.0&lt;/P&gt;&lt;P&gt;I restarted PIX, clear xlate, but nothing help me.&lt;/P&gt;&lt;P&gt;show route show me:&lt;/P&gt;&lt;P&gt;route inside 192.168.1.0 255.255.255.0 192.168.4.100 other&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried route inside 192.168.1.100 255.255.255.255 192.168.4.100 but nothing happend.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 12 Mar 2005 13:00:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-route-on-pix/m-p/315361#M550576</guid>
      <dc:creator>milan.zmarzlak</dc:creator>
      <dc:date>2005-03-12T13:00:17Z</dc:date>
    </item>
    <item>
      <title>Re: static route on PIX</title>
      <link>https://community.cisco.com/t5/network-security/static-route-on-pix/m-p/315362#M550577</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have default route set to PIX IP address in both the hosts?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 Mar 2005 00:45:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-route-on-pix/m-p/315362#M550577</guid>
      <dc:creator>rais</dc:creator>
      <dc:date>2005-03-13T00:45:38Z</dc:date>
    </item>
    <item>
      <title>Re: static route on PIX</title>
      <link>https://community.cisco.com/t5/network-security/static-route-on-pix/m-p/315363#M550578</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am afraid it is not possible to use the PIX this way. Traffic arriving at a PIX interface can not be forwarded back through the same interface.&lt;/P&gt;&lt;P&gt;This is explained in the PIX FAQ document here, in an answer to "Can I operate the PIX in a "one armed" configuration?":&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_qanda_item09186a0080094874.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_qanda_item09186a0080094874.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have a vlan-capable switch, you can try setting up vlan interfaces on the PIX (PIX 501 won't work), one vlan for the first lan and another vlan for the router:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_configuration_guide_chapter09186a0080172786.html#wp1113437" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_configuration_guide_chapter09186a0080172786.html#wp1113437&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Mustafa&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 Mar 2005 02:35:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-route-on-pix/m-p/315363#M550578</guid>
      <dc:creator>mhussein</dc:creator>
      <dc:date>2005-03-13T02:35:24Z</dc:date>
    </item>
    <item>
      <title>Re: static route on PIX</title>
      <link>https://community.cisco.com/t5/network-security/static-route-on-pix/m-p/315364#M550579</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Mustafa. I concur with you 100%.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 Mar 2005 15:08:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-route-on-pix/m-p/315364#M550579</guid>
      <dc:creator>rais</dc:creator>
      <dc:date>2005-03-13T15:08:18Z</dc:date>
    </item>
    <item>
      <title>Re: static route on PIX</title>
      <link>https://community.cisco.com/t5/network-security/static-route-on-pix/m-p/315365#M550581</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for all. I believe that this help me.&lt;/P&gt;&lt;P&gt;Milan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Mar 2005 06:41:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-route-on-pix/m-p/315365#M550581</guid>
      <dc:creator>milan.zmarzlak</dc:creator>
      <dc:date>2005-03-14T06:41:24Z</dc:date>
    </item>
    <item>
      <title>Re: static route on PIX</title>
      <link>https://community.cisco.com/t5/network-security/static-route-on-pix/m-p/315366#M550583</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have no experience with VLAN, can anybody help me?&lt;/P&gt;&lt;P&gt;that is my configuration on PIX, in this LAN I've Cisco Router 192.168.4.100:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX Version 6.3(3)133&lt;/P&gt;&lt;P&gt;interface ethernet0 auto&lt;/P&gt;&lt;P&gt;interface ethernet1 auto&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;hostname xxx&lt;/P&gt;&lt;P&gt;domain-name xxx&lt;/P&gt;&lt;P&gt;fixup protocol dns maximum-length 512&lt;/P&gt;&lt;P&gt;fixup protocol ftp 21&lt;/P&gt;&lt;P&gt;fixup protocol h323 h225 1720&lt;/P&gt;&lt;P&gt;fixup protocol h323 ras 1718-1719&lt;/P&gt;&lt;P&gt;fixup protocol http 80&lt;/P&gt;&lt;P&gt;fixup protocol rsh 514&lt;/P&gt;&lt;P&gt;fixup protocol rtsp 554&lt;/P&gt;&lt;P&gt;fixup protocol sip 5060&lt;/P&gt;&lt;P&gt;fixup protocol sip udp 5060&lt;/P&gt;&lt;P&gt;fixup protocol skinny 2000&lt;/P&gt;&lt;P&gt;fixup protocol smtp 25&lt;/P&gt;&lt;P&gt;fixup protocol sqlnet 1521&lt;/P&gt;&lt;P&gt;fixup protocol tftp 69&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;object-group service mail tcp &lt;/P&gt;&lt;P&gt;  port-object eq pop3 &lt;/P&gt;&lt;P&gt;  port-object eq smtp &lt;/P&gt;&lt;P&gt;access-list outbound01 permit icmp any any &lt;/P&gt;&lt;P&gt;access-list outbound01 permit tcp 192.168.4.0 255.255.255.0 any eq domain &lt;/P&gt;&lt;P&gt;access-list outbound01 permit udp 192.168.4.0 255.255.255.0 any eq domain &lt;/P&gt;&lt;P&gt;access-list outbound01 permit tcp 192.168.4.0 255.255.255.0 any eq aol &lt;/P&gt;&lt;P&gt;access-list outbound01 permit tcp any any eq ssh &lt;/P&gt;&lt;P&gt;access-list outbound01 permit tcp 192.168.4.0 255.255.255.0 any eq lotusnotes &lt;/P&gt;&lt;P&gt;access-list outbound01 permit tcp 192.168.4.0 255.255.255.0 any eq www &lt;/P&gt;&lt;P&gt;access-list outbound01 permit tcp 192.168.4.0 255.255.255.0 any eq https &lt;/P&gt;&lt;P&gt;access-list outbound01 permit tcp 192.168.4.0 255.255.255.0 any eq 3389 &lt;/P&gt;&lt;P&gt;access-list outbound01 permit tcp 192.168.4.0 255.255.255.0 any eq 2439 &lt;/P&gt;&lt;P&gt;access-list outbound01 permit tcp 192.168.4.0 255.255.255.0 any eq pop3 &lt;/P&gt;&lt;P&gt;access-list outbound01 permit tcp 192.168.4.0 255.255.255.0 any eq smtp &lt;/P&gt;&lt;P&gt;access-list inbound01 permit icmp any any &lt;/P&gt;&lt;P&gt;access-list inbound01 deny ip any any &lt;/P&gt;&lt;P&gt;access-list inside_outbound_nat0_acl permit ip any 192.168.4.96 255.255.255.224 &lt;/P&gt;&lt;P&gt;access-list inside_outbound_nat0_acl permit ip any 192.168.4.96 255.255.255.248 &lt;/P&gt;&lt;P&gt;access-list outside_cryptomap_dyn_100 permit ip any 192.168.4.96 255.255.255.248 &lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging on&lt;/P&gt;&lt;P&gt;logging standby&lt;/P&gt;&lt;P&gt;logging console debugging&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;ip address outside 194.212.x.x 255.255.255.252&lt;/P&gt;&lt;P&gt;ip address inside 192.168.4.1 255.255.255.0&lt;/P&gt;&lt;P&gt;ip audit info action alarm&lt;/P&gt;&lt;P&gt;ip audit attack action alarm&lt;/P&gt;&lt;P&gt;pdm location 192.168.4.143 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;pdm location 192.168.4.187 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;pdm logging informational 100&lt;/P&gt;&lt;P&gt;pdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 1 192.168.4.0 255.255.255.0 0 0&lt;/P&gt;&lt;P&gt;access-group inbound01 in interface outside&lt;/P&gt;&lt;P&gt;access-group outbound01 in interface inside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 194.212.103.105 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server community public&lt;/P&gt;&lt;P&gt;no snmp-server enable traps&lt;/P&gt;&lt;P&gt;floodguard enable&lt;/P&gt;&lt;P&gt;sysopt connection permit-ipsec&lt;/P&gt;&lt;P&gt;sysopt connection permit-pptp&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac &lt;/P&gt;&lt;P&gt;crypto dynamic-map outside_dyn_map 20 set transform-set ESP-3DES-MD5&lt;/P&gt;&lt;P&gt;crypto dynamic-map outside_dyn_map 40 set transform-set ESP-3DES-MD5&lt;/P&gt;&lt;P&gt;crypto dynamic-map outside_dyn_map 60 set transform-set ESP-3DES-MD5&lt;/P&gt;&lt;P&gt;crypto dynamic-map outside_dyn_map 80 set pfs group2&lt;/P&gt;&lt;P&gt;crypto dynamic-map outside_dyn_map 80 set transform-set ESP-3DES-MD5&lt;/P&gt;&lt;P&gt;crypto dynamic-map outside_dyn_map 100 match address outside_cryptomap_dyn_100&lt;/P&gt;&lt;P&gt;crypto dynamic-map outside_dyn_map 100 set transform-set ESP-3DES-MD5&lt;/P&gt;&lt;P&gt;crypto map outside_map 65535 ipsec-isakmp dynamic outside_dyn_map&lt;/P&gt;&lt;P&gt;crypto map outside_map client authentication LOCAL&lt;/P&gt;&lt;P&gt;crypto map outside_map interface outside&lt;/P&gt;&lt;P&gt;isakmp enable outside&lt;/P&gt;&lt;P&gt;isakmp policy 20 authentication pre-share&lt;/P&gt;&lt;P&gt;isakmp policy 20 encryption 3des&lt;/P&gt;&lt;P&gt;isakmp policy 20 hash md5&lt;/P&gt;&lt;P&gt;isakmp policy 20 group 2&lt;/P&gt;&lt;P&gt;isakmp policy 20 lifetime 86400&lt;/P&gt;&lt;P&gt;telnet 192.168.4.187 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh 192.168.4.143 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;ssh timeout 30&lt;/P&gt;&lt;P&gt;dhcpd address 192.168.4.129-192.168.4.254 inside&lt;/P&gt;&lt;P&gt;dhcpd dns 212.65.x.x212.65.x.x&lt;/P&gt;&lt;P&gt;dhcpd lease 43200&lt;/P&gt;&lt;P&gt;dhcpd ping_timeout 750&lt;/P&gt;&lt;P&gt;dhcpd domain xxx&lt;/P&gt;&lt;P&gt;dhcpd enable inside&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Mar 2005 08:02:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-route-on-pix/m-p/315366#M550583</guid>
      <dc:creator>milan.zmarzlak</dc:creator>
      <dc:date>2005-03-14T08:02:32Z</dc:date>
    </item>
    <item>
      <title>Re: static route on PIX</title>
      <link>https://community.cisco.com/t5/network-security/static-route-on-pix/m-p/315367#M550584</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Now things look doable to me. Are you saying your router has two IP addresses: 192.168.4.100 and 192.168.1.100? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If answer to the above is affirmative then simply point default route of internal hosts to the Cisco router (not the PIX) and point the router's default gateway to the PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does it make sense?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Mar 2005 12:39:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-route-on-pix/m-p/315367#M550584</guid>
      <dc:creator>rais</dc:creator>
      <dc:date>2005-03-14T12:39:36Z</dc:date>
    </item>
  </channel>
</rss>

