<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX routing between VLANS in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-routing-between-vlans/m-p/338825#M553120</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have exactly same problem. We have dmz-interface, 2 vlans used. Physical vlan is 100 (DMZ) and logical 200 (DMZ2).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Security levels are:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DMZ = 50&lt;/P&gt;&lt;P&gt;DMZ2 = 60&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When connecting from DMZ2 to DMZ I get that 110001 log message saying there's no route from DMZ2 to DMZ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When connecting from DMZ to DMZ2, I get "Built outbound TCP connection" -message saying that connection is built, but right after comes "Deny TCP (no connection)" -message...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh route -command gives following output regarding to those interfaces:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C       10.100.100.0  is directly connected, DMZ&lt;/P&gt;&lt;P&gt;C       10.200.200.0  is directly connected, DMZ2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I'd say that those should see each other...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Following traffic goes alright:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DMZ --&amp;gt; Inside&lt;/P&gt;&lt;P&gt;DMZ2 --&amp;gt; Inside&lt;/P&gt;&lt;P&gt;DMZ --&amp;gt; Outside&lt;/P&gt;&lt;P&gt;DMZ2 --&amp;gt; Outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Access-lists and nat/globals are configured so that everything should work, but...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this some sort of bug? Can't PIX route traffic on vlans? I'm puzzled, please if someone has any suggestions I'd be very delighted...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*******&lt;/P&gt;&lt;P&gt;Saska&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 05 Jan 2005 07:53:40 GMT</pubDate>
    <dc:creator>svuorilehto</dc:creator>
    <dc:date>2005-01-05T07:53:40Z</dc:date>
    <item>
      <title>PIX routing between VLANS</title>
      <link>https://community.cisco.com/t5/network-security/pix-routing-between-vlans/m-p/338823#M553118</link>
      <description>&lt;P&gt;I&amp;#146;m trying to configure the following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a Pix525 with 3 physical interfaces. The DMZ interface is configured for VLANS. Only 2 vlans are used, native (matching up to VLAN1 on my switch) is used for my DMZ servers and VLAN 55 is used to connect to a VPN 3005. A /30 is used to number VLAN 55 on the PIX to the private interface on the VPN 3005. A /24 is statically routed from the PIX, pointing to the IP address on private interface for use by various VPN clients.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My problem is that when I try to access anything from the VPN client /24 going to the DMZ interface, I get this error in the firewall log:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;%PIX-6-110001: No route to 10.101.0.5 from 10.1.2.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can access everything from the VPN on the internal interface, I can&amp;#146;t figure out what&amp;#146;s misconfigured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The security setting for the interfaces are configured as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dmz = 50&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vpn = 25&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help will be greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:50:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-routing-between-vlans/m-p/338823#M553118</guid>
      <dc:creator>jmarr</dc:creator>
      <dc:date>2020-02-21T07:50:17Z</dc:date>
    </item>
    <item>
      <title>Re: PIX routing between VLANS</title>
      <link>https://community.cisco.com/t5/network-security/pix-routing-between-vlans/m-p/338824#M553119</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Call me nutty - but I'm guessing the PIX has no route between those 2 subnets &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;  How are you routing between the 2 VLANS?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Jan 2005 20:27:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-routing-between-vlans/m-p/338824#M553119</guid>
      <dc:creator>arousch.sprint</dc:creator>
      <dc:date>2005-01-03T20:27:05Z</dc:date>
    </item>
    <item>
      <title>Re: PIX routing between VLANS</title>
      <link>https://community.cisco.com/t5/network-security/pix-routing-between-vlans/m-p/338825#M553120</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have exactly same problem. We have dmz-interface, 2 vlans used. Physical vlan is 100 (DMZ) and logical 200 (DMZ2).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Security levels are:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DMZ = 50&lt;/P&gt;&lt;P&gt;DMZ2 = 60&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When connecting from DMZ2 to DMZ I get that 110001 log message saying there's no route from DMZ2 to DMZ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When connecting from DMZ to DMZ2, I get "Built outbound TCP connection" -message saying that connection is built, but right after comes "Deny TCP (no connection)" -message...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh route -command gives following output regarding to those interfaces:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C       10.100.100.0  is directly connected, DMZ&lt;/P&gt;&lt;P&gt;C       10.200.200.0  is directly connected, DMZ2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I'd say that those should see each other...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Following traffic goes alright:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DMZ --&amp;gt; Inside&lt;/P&gt;&lt;P&gt;DMZ2 --&amp;gt; Inside&lt;/P&gt;&lt;P&gt;DMZ --&amp;gt; Outside&lt;/P&gt;&lt;P&gt;DMZ2 --&amp;gt; Outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Access-lists and nat/globals are configured so that everything should work, but...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this some sort of bug? Can't PIX route traffic on vlans? I'm puzzled, please if someone has any suggestions I'd be very delighted...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*******&lt;/P&gt;&lt;P&gt;Saska&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Jan 2005 07:53:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-routing-between-vlans/m-p/338825#M553120</guid>
      <dc:creator>svuorilehto</dc:creator>
      <dc:date>2005-01-05T07:53:40Z</dc:date>
    </item>
    <item>
      <title>Re: PIX routing between VLANS</title>
      <link>https://community.cisco.com/t5/network-security/pix-routing-between-vlans/m-p/338826#M553121</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Our PIXs route fine vlan-vlan.  Our configuration is &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface ethernet3 vlan90 physical&lt;/P&gt;&lt;P&gt;interface ethernet3 vlan96 logical&lt;/P&gt;&lt;P&gt;interface ethernet3 vlan97 logical&lt;/P&gt;&lt;P&gt;interface ethernet3 vlan98 logical&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;nameif ethernet0 inside security100&lt;/P&gt;&lt;P&gt;nameif ethernet1 Failover security80&lt;/P&gt;&lt;P&gt;nameif ethernet2 StateFull security85&lt;/P&gt;&lt;P&gt;nameif ethernet3 v security0&lt;/P&gt;&lt;P&gt;nameif vlan96 x security25&lt;/P&gt;&lt;P&gt;nameif vlan97 y security50&lt;/P&gt;&lt;P&gt;nameif vlan98 z security0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;whereas vlan90 isn't a traffic carying vlan.  So difference would be you're routing between physical to logical; I'm routing between logical to logical.  You might try to convert vlan 100 to a logical vlan, see if it makes a difference.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Jan 2005 00:48:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-routing-between-vlans/m-p/338826#M553121</guid>
      <dc:creator>klwilson</dc:creator>
      <dc:date>2005-01-06T00:48:05Z</dc:date>
    </item>
    <item>
      <title>Re: PIX routing between VLANS</title>
      <link>https://community.cisco.com/t5/network-security/pix-routing-between-vlans/m-p/338827#M553122</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi there, and thanks for the answer!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried that change from physical to logical, but still no effect...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What PIX version are you using? We have 6.3(1).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*******&lt;/P&gt;&lt;P&gt;Saska&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Jan 2005 07:48:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-routing-between-vlans/m-p/338827#M553122</guid>
      <dc:creator>svuorilehto</dc:creator>
      <dc:date>2005-01-07T07:48:25Z</dc:date>
    </item>
    <item>
      <title>Re: PIX routing between VLANS</title>
      <link>https://community.cisco.com/t5/network-security/pix-routing-between-vlans/m-p/338828#M553123</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;6.3(3).  Can you post a config to look at?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Jan 2005 17:31:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-routing-between-vlans/m-p/338828#M553123</guid>
      <dc:creator>klwilson</dc:creator>
      <dc:date>2005-01-10T17:31:07Z</dc:date>
    </item>
    <item>
      <title>Re: PIX routing between VLANS</title>
      <link>https://community.cisco.com/t5/network-security/pix-routing-between-vlans/m-p/338829#M553125</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi and thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's our config, at least strongly edited one... I have included lines I think are relevant, if there are any others you would like to examine, please let me know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are no route lines, because both interfaces are directly connected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*******&lt;/P&gt;&lt;P&gt;Saska&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;----------------clip--------------------&lt;/P&gt;&lt;P&gt;PIX Version 6.3(1)&lt;/P&gt;&lt;P&gt;interface ethernet0 100full&lt;/P&gt;&lt;P&gt;interface ethernet1 100full&lt;/P&gt;&lt;P&gt;interface ethernet2 100full&lt;/P&gt;&lt;P&gt;interface ethernet2 vlan200 logical&lt;/P&gt;&lt;P&gt;interface ethernet2 vlan100 logical&lt;/P&gt;&lt;P&gt;interface ethernet3 auto shutdown&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;nameif ethernet2 intf7 security14&lt;/P&gt;&lt;P&gt;nameif ethernet3 intf3 security15&lt;/P&gt;&lt;P&gt;nameif vlan200 DMZ2 security60&lt;/P&gt;&lt;P&gt;nameif vlan100 DMZ security50 &lt;/P&gt;&lt;P&gt;no ip address intf3&lt;/P&gt;&lt;P&gt;no ip address intf7&lt;/P&gt;&lt;P&gt;ip address DMZ2 10.200.200.1 255.255.255.224&lt;/P&gt;&lt;P&gt;ip address DMZ 10.100.100.1 255.255.255.0&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list NO_NAT_INSIDE&lt;/P&gt;&lt;P&gt;nat (DMZ2) 0 10.200.200.0 255.255.255.224 0 0&lt;/P&gt;&lt;P&gt;nat (DMZ) 0 access-list NO_NAT_DMZ&lt;/P&gt;&lt;P&gt;static (inside,DMZ2) 10.18.0.0 10.18.0.0 netmask 255.255.0.0 0 0 &lt;/P&gt;&lt;P&gt;static (DMZ2,DMZ) 10.200.200.0 10.200.200.0 netmask 255.255.255.224 0 0&lt;/P&gt;&lt;P&gt;----------------clip--------------------&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Jan 2005 07:29:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-routing-between-vlans/m-p/338829#M553125</guid>
      <dc:creator>svuorilehto</dc:creator>
      <dc:date>2005-01-11T07:29:25Z</dc:date>
    </item>
  </channel>
</rss>

