<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Route in/out same interface on PIX in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/route-in-out-same-interface-on-pix/m-p/483671#M556963</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Intra-interface firewalling is possible on both FWSM 2.3 amd PIX 7.0 using the 'same-security-traffic permit intra-interface' command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the FWSM this can be for any traffic. However on the PIX I beleive this is allowed only for IPSec traffic - VPN Hub-Spoke scenario to allow for spoke-spoke communication after firewalling on same interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 01 Jul 2005 22:26:49 GMT</pubDate>
    <dc:creator>sunilc</dc:creator>
    <dc:date>2005-07-01T22:26:49Z</dc:date>
    <item>
      <title>Route in/out same interface on PIX</title>
      <link>https://community.cisco.com/t5/network-security/route-in-out-same-interface-on-pix/m-p/483665#M556955</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was recently told that it is not possible to route traffic coming in via e.g. Eth1 out of Eth1 again to another router for example.&lt;/P&gt;&lt;P&gt;I'm not convinced though, and was wondering if any of you know of a way to do it? It is some special command, a question of rules or simply the need for a firmware update?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;Rasmus&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:13:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/route-in-out-same-interface-on-pix/m-p/483665#M556955</guid>
      <dc:creator>rate</dc:creator>
      <dc:date>2020-02-21T08:13:08Z</dc:date>
    </item>
    <item>
      <title>Re: Route in/out same interface on PIX</title>
      <link>https://community.cisco.com/t5/network-security/route-in-out-same-interface-on-pix/m-p/483666#M556956</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Rasmus&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are right... icmp redirects arent possible with PIX.. this is feature specific and does not depend on any commands or hardware...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;try putting a router before/after pix and do redirection on router instead of pix...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;just have a look at this pix faq document..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Raj&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Jun 2005 09:25:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/route-in-out-same-interface-on-pix/m-p/483666#M556956</guid>
      <dc:creator>sachinraja</dc:creator>
      <dc:date>2005-06-20T09:25:15Z</dc:date>
    </item>
    <item>
      <title>Re: Route in/out same interface on PIX</title>
      <link>https://community.cisco.com/t5/network-security/route-in-out-same-interface-on-pix/m-p/483667#M556957</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I had the same need a little over a year ago and I opened a TAC case to ask if there were any "undocumented commands" to get the PIX to route packets in/out, for my particular SOHO need.  I was advised it was NOT possible.  I had to put a router just before the PIX, as has been mentioned in this thread.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Jun 2005 13:43:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/route-in-out-same-interface-on-pix/m-p/483667#M556957</guid>
      <dc:creator>s309973</dc:creator>
      <dc:date>2005-06-27T13:43:37Z</dc:date>
    </item>
    <item>
      <title>Re: Route in/out same interface on PIX</title>
      <link>https://community.cisco.com/t5/network-security/route-in-out-same-interface-on-pix/m-p/483668#M556958</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Routing packets in/out of the same interface is known as hair-pinning. This is not supported in 6.x or previous versions, but you can enable it on PIX 7.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Jun 2005 14:16:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/route-in-out-same-interface-on-pix/m-p/483668#M556958</guid>
      <dc:creator>timothy.arnold</dc:creator>
      <dc:date>2005-06-27T14:16:28Z</dc:date>
    </item>
    <item>
      <title>Re: Route in/out same interface on PIX</title>
      <link>https://community.cisco.com/t5/network-security/route-in-out-same-interface-on-pix/m-p/483669#M556959</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Really? That sounds great. Actually I think it weird they didn't implement it in earlier versions - a lot of other firewalls can do it.&lt;/P&gt;&lt;P&gt;Is it easy to configure, or is it rocket science?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jun 2005 06:00:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/route-in-out-same-interface-on-pix/m-p/483669#M556959</guid>
      <dc:creator>rate</dc:creator>
      <dc:date>2005-06-28T06:00:46Z</dc:date>
    </item>
    <item>
      <title>Re: Route in/out same interface on PIX</title>
      <link>https://community.cisco.com/t5/network-security/route-in-out-same-interface-on-pix/m-p/483670#M556961</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can enable hair-pinning ONLY for VPN....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jun 2005 08:18:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/route-in-out-same-interface-on-pix/m-p/483670#M556961</guid>
      <dc:creator>a.alekseev</dc:creator>
      <dc:date>2005-06-28T08:18:17Z</dc:date>
    </item>
    <item>
      <title>Re: Route in/out same interface on PIX</title>
      <link>https://community.cisco.com/t5/network-security/route-in-out-same-interface-on-pix/m-p/483671#M556963</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Intra-interface firewalling is possible on both FWSM 2.3 amd PIX 7.0 using the 'same-security-traffic permit intra-interface' command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the FWSM this can be for any traffic. However on the PIX I beleive this is allowed only for IPSec traffic - VPN Hub-Spoke scenario to allow for spoke-spoke communication after firewalling on same interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Jul 2005 22:26:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/route-in-out-same-interface-on-pix/m-p/483671#M556963</guid>
      <dc:creator>sunilc</dc:creator>
      <dc:date>2005-07-01T22:26:49Z</dc:date>
    </item>
  </channel>
</rss>

