<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX and OSPF in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-and-ospf/m-p/472252#M558115</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;PIX doesn't allow broadcast and multicast traffic to pass through it. Therefore, we can't use an Interior Gateway Protocol (IGP) such as Open Shortest Path First (OSPF), Enhanced Interior Gateway Routing Protocol (EIGRP), or Routing Information Protocol (RIP), all of which use broadcast and multicast packets to exchange routing information.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 24 May 2005 20:57:36 GMT</pubDate>
    <dc:creator>didyap</dc:creator>
    <dc:date>2005-05-24T20:57:36Z</dc:date>
    <item>
      <title>PIX and OSPF</title>
      <link>https://community.cisco.com/t5/network-security/pix-and-ospf/m-p/472251#M558106</link>
      <description>&lt;P&gt;I have 1 router configured with BGP that is then connected to a PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IP Block A is a class C that is has a /27 subnet used for loopback and numbered link addressing. A portion of the block is used on my PIX for static NAT translations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have OSPF configured on the PIX and the router. IP block is statically routed to NULL with a metric of 254 (for BGP announcements) on the router. I have a static route on the PIX pointing the entire class C to the outside interface. This route is redistributed into OSPF with a metric of 200. The intention of this is so that the router would see the announcement from the PIX, keeping me from putting a 2nd static route on the router pointing it to the PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My problem is that when I reboot the pix and it comes backup, internal hosts can not reach the /27 network and external hosts cannot reach the nat translated addresses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question, What is the proper way of "routing" nat translated IPs? I guess they are currently being proxy arped by the PIX. I would prefer that I use OSPF to get the traffic from the router to the PIX, but maybe this isn't feasible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:09:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-and-ospf/m-p/472251#M558106</guid>
      <dc:creator>joemarr_brodart</dc:creator>
      <dc:date>2020-02-21T08:09:12Z</dc:date>
    </item>
    <item>
      <title>Re: PIX and OSPF</title>
      <link>https://community.cisco.com/t5/network-security/pix-and-ospf/m-p/472252#M558115</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;PIX doesn't allow broadcast and multicast traffic to pass through it. Therefore, we can't use an Interior Gateway Protocol (IGP) such as Open Shortest Path First (OSPF), Enhanced Interior Gateway Routing Protocol (EIGRP), or Routing Information Protocol (RIP), all of which use broadcast and multicast packets to exchange routing information.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 May 2005 20:57:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-and-ospf/m-p/472252#M558115</guid>
      <dc:creator>didyap</dc:creator>
      <dc:date>2005-05-24T20:57:36Z</dc:date>
    </item>
  </channel>
</rss>

