<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic two gateways in a PIX in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/two-gateways-in-a-pix/m-p/431747#M557373</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I would like to have two wan routers in the outside network of my pix, and perform a basic polic based routing, I mean, depends on what IP is going to the internet, the router send the packets to one default router or to another.&lt;/P&gt;&lt;P&gt;Is that config possible ??&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Luis Miguel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 08:11:29 GMT</pubDate>
    <dc:creator>lmgil</dc:creator>
    <dc:date>2020-02-21T08:11:29Z</dc:date>
    <item>
      <title>two gateways in a PIX</title>
      <link>https://community.cisco.com/t5/network-security/two-gateways-in-a-pix/m-p/431747#M557373</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I would like to have two wan routers in the outside network of my pix, and perform a basic polic based routing, I mean, depends on what IP is going to the internet, the router send the packets to one default router or to another.&lt;/P&gt;&lt;P&gt;Is that config possible ??&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Luis Miguel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:11:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-gateways-in-a-pix/m-p/431747#M557373</guid>
      <dc:creator>lmgil</dc:creator>
      <dc:date>2020-02-21T08:11:29Z</dc:date>
    </item>
    <item>
      <title>Re: two gateways in a PIX</title>
      <link>https://community.cisco.com/t5/network-security/two-gateways-in-a-pix/m-p/431748#M557375</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is about the only way you can use a single pix (or failover bundle) to handle two internet connections each with their own IP allocation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The main issue to be resolved is not the outbound policy routing, mapping IP to correct ISP, which is straight forward, but the detection and handling of the various points of failure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I set up two 2600 with 3 interfaces each:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Inside interfaces presenting a single IP via HSRP, tracking the ISP interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Router-router interfaces running an IGP routing protocol&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISP-facing interfaces which need to be directly connected to the ISP router if you want to detect interface down.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Its not very elegant, so I waited for PIX 7 because I was told that it would be able to support policy routing, but it was not so &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Jun 2005 14:12:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-gateways-in-a-pix/m-p/431748#M557375</guid>
      <dc:creator>Philip DG</dc:creator>
      <dc:date>2005-06-06T14:12:26Z</dc:date>
    </item>
    <item>
      <title>Re: two gateways in a PIX</title>
      <link>https://community.cisco.com/t5/network-security/two-gateways-in-a-pix/m-p/431749#M557376</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes, it's possible.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Jun 2005 20:44:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-gateways-in-a-pix/m-p/431749#M557376</guid>
      <dc:creator>a.alekseev</dc:creator>
      <dc:date>2005-06-06T20:44:11Z</dc:date>
    </item>
    <item>
      <title>Re: two gateways in a PIX</title>
      <link>https://community.cisco.com/t5/network-security/two-gateways-in-a-pix/m-p/431750#M557377</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you clarify how ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Jun 2005 08:17:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-gateways-in-a-pix/m-p/431750#M557377</guid>
      <dc:creator>lmgil</dc:creator>
      <dc:date>2005-06-07T08:17:19Z</dc:date>
    </item>
    <item>
      <title>Re: two gateways in a PIX</title>
      <link>https://community.cisco.com/t5/network-security/two-gateways-in-a-pix/m-p/431751#M557378</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Regarding the detection of failure...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check this page:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/tech/tk364/technologies_configuration_example09186a0080211f5c.shtml" target="_blank"&gt;http://www.cisco.com/en/US/tech/tk364/technologies_configuration_example09186a0080211f5c.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you run a routing-protocol against the ISP's it's even easier.. you don't have to do ping-tests.. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I haven't seen any policy-routing in the PIX either..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;v7.0 has ECMP support for up to 3 equal-cost gateways, but they are just load-balanced and has to be on the same interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jun 2005 13:53:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-gateways-in-a-pix/m-p/431751#M557378</guid>
      <dc:creator>johansens</dc:creator>
      <dc:date>2005-06-14T13:53:52Z</dc:date>
    </item>
    <item>
      <title>Re: two gateways in a PIX</title>
      <link>https://community.cisco.com/t5/network-security/two-gateways-in-a-pix/m-p/431752#M557379</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;PRE&gt;&lt;/PRE&gt;&lt;/P&gt;&lt;P&gt;isp1-------R1----.2------|&lt;/P&gt;&lt;P&gt;            |            |&lt;/P&gt;&lt;P&gt;            |    HSRP .1 |---------.4-PIX------&lt;/P&gt;&lt;P&gt;            |            |&lt;/P&gt;&lt;P&gt;isp2-------R2----.3------|&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you can run OSPF between R1,R2,PIX or use default route to HSRP-ip-addreess&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;odd inside hosts will be translated to ISP1 address space&lt;/P&gt;&lt;P&gt;nat(inside) 1 0.0.0.1 0.0.0.1&lt;/P&gt;&lt;P&gt;global(outside) 1 ISP1-ip-address&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;even inside hosts will be translated to ISP2 address space &lt;/P&gt;&lt;P&gt;nat(inside) 2 0.0.0.0 0.0.0.1&lt;/P&gt;&lt;P&gt;global(outside) 2 ISP2-ip-address&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;on R1, R2 you must have policy-routing.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 19 Jun 2005 17:00:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-gateways-in-a-pix/m-p/431752#M557379</guid>
      <dc:creator>a.alekseev</dc:creator>
      <dc:date>2005-06-19T17:00:36Z</dc:date>
    </item>
    <item>
      <title>Re: two gateways in a PIX</title>
      <link>https://community.cisco.com/t5/network-security/two-gateways-in-a-pix/m-p/431753#M557380</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Luis,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm no PIX expert, but I believe you can achieve what you are refering to by using Policy NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See the last config example called "Use Policy NAT" in the following URL.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/partner/products/hw/vpndevc/ps2030/products_tech_note09186a008046f31a.shtml" target="_blank"&gt;http://www.cisco.com/en/US/partner/products/hw/vpndevc/ps2030/products_tech_note09186a008046f31a.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;You may also have a LOT more flexibility determining which local IP ranges to use in your policy decisions with PIX OS v7.0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Dave.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Jun 2005 09:59:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-gateways-in-a-pix/m-p/431753#M557380</guid>
      <dc:creator>david-wood</dc:creator>
      <dc:date>2005-06-20T09:59:00Z</dc:date>
    </item>
  </channel>
</rss>

