<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Strange routing issue in PIX501 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/strange-routing-issue-in-pix501/m-p/1596423#M559958</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Imran,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, option is not a very scalable solution. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well, i guess you are right. We can use PIX as the gatway for all traffic and u turn traffic for corporate network to the router. We might have to check possiblity of Assymerteric routing for the return traffic. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) PIX will be gateway for all&lt;/P&gt;&lt;P&gt;2) route inside -&amp;gt; router for corp network&lt;/P&gt;&lt;P&gt;3) tcp state bypass will be required on the firewall&lt;/P&gt;&lt;P&gt;4) UDP traffic will get dropped due to assymeteric routing, so we will require a local DNS server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another option is to utilize 2 ISPs on the PIX on 2 different interfaces. Configure 2 interfaces say out1 &amp;amp; out2 at security level 0. One will be for internet and other will be for IPSec tunnel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps. Please reply back if you need any further assistance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Chirag&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;P.S.: Please mark this thread as answered if you feel your query is answered. Do rate helpful posts.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 15 Mar 2011 14:43:42 GMT</pubDate>
    <dc:creator>csaxena</dc:creator>
    <dc:date>2011-03-15T14:43:42Z</dc:date>
    <item>
      <title>Strange routing issue in PIX501</title>
      <link>https://community.cisco.com/t5/network-security/strange-routing-issue-in-pix501/m-p/1596420#M559953</link>
      <description>&lt;P&gt;Hi gurus,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am having trouble with routing in PIX501&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have one Pix 501 and one Cisco router&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco Router is configured for IPSEC VPN &lt;STRONG&gt;( LAN interface 172.19.194.1)&lt;/STRONG&gt;&amp;nbsp; and PIX is configured for access the internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Default gateway of Pcs in LAN are PIX inside interface &lt;STRONG&gt;( 172.19.194.2)&lt;/STRONG&gt; but people are unable to access to corporate network but can access the internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below is the route command configured on the PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;route inside 172.19.206.0 255.255.255.0 172.19.194.1 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If i set default gateway to Cisco router&amp;nbsp; LAN interface &lt;STRONG&gt;( 172.19.194.1)&lt;/STRONG&gt;then i can access to corporate network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Purpose is to pass the internet traffic using PIX 501 and corporate network traffic using Cisco router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can any one help me in this regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have attached the diagram for the network&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:07:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-routing-issue-in-pix501/m-p/1596420#M559953</guid>
      <dc:creator>imranbhatti151</dc:creator>
      <dc:date>2019-03-11T20:07:02Z</dc:date>
    </item>
    <item>
      <title>Re: Strange routing issue in PIX501</title>
      <link>https://community.cisco.com/t5/network-security/strange-routing-issue-in-pix501/m-p/1596421#M559955</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Imran,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If i get the requirement right,you need to access internet using PIX(.2) as the gateway and while accessing corporate network, i.e. over the IPSec tunnel using router(.1) as gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;One option&lt;/STRONG&gt; is to set routes on work station for corp network. For e.g. for a windows machine, say ur corp network is 10.0.0.0/8 network, then add&lt;/P&gt;&lt;P&gt;route -add &lt;NETWORK&gt; mask &lt;NETMASK&gt; &lt;GATEWAY&gt;&lt;/GATEWAY&gt;&lt;/NETMASK&gt;&lt;/NETWORK&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For more help, refer : &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/sag_tcpip_pro_addstaticroute.mspx?mfr=true"&gt;http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/sag_tcpip_pro_addstaticroute.mspx?mfr=true&lt;/A&gt;&lt;/P&gt;&lt;P&gt;This option is feasible in small work/home environment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Other option&lt;/STRONG&gt; is to use PIX in the network alone, and utilize another interface to terminate VPN and do routing on PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;One more option&lt;/STRONG&gt;, will cost an extra device, add router in the network before both the gateways and do Policy Based Routing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps. Please reply back if you need any further assistance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Chirag&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;P.S.: Please mark this thread as answered if you feel your query is answered. Do rate helpful posts.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Mar 2011 13:58:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-routing-issue-in-pix501/m-p/1596421#M559955</guid>
      <dc:creator>csaxena</dc:creator>
      <dc:date>2011-03-15T13:58:17Z</dc:date>
    </item>
    <item>
      <title>Re: Strange routing issue in PIX501</title>
      <link>https://community.cisco.com/t5/network-security/strange-routing-issue-in-pix501/m-p/1596422#M559957</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Saxena,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply and you understand correctly about my understandings&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand option number one but it is not feasible i think.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;But i want to know why&amp;nbsp; i cannot use PIX as a routing device in this case as i used now.&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Actually i have two different Internet connections ( i want to utilise one for IPSEC and second for internet browsing).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Terminating VPN on pix is not attractive for me .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If i add another router, still i need to have policy based routing or simple routing will be enough.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking for your support&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Mar 2011 14:23:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-routing-issue-in-pix501/m-p/1596422#M559957</guid>
      <dc:creator>imranbhatti151</dc:creator>
      <dc:date>2011-03-15T14:23:46Z</dc:date>
    </item>
    <item>
      <title>Re: Strange routing issue in PIX501</title>
      <link>https://community.cisco.com/t5/network-security/strange-routing-issue-in-pix501/m-p/1596423#M559958</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Imran,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, option is not a very scalable solution. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well, i guess you are right. We can use PIX as the gatway for all traffic and u turn traffic for corporate network to the router. We might have to check possiblity of Assymerteric routing for the return traffic. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) PIX will be gateway for all&lt;/P&gt;&lt;P&gt;2) route inside -&amp;gt; router for corp network&lt;/P&gt;&lt;P&gt;3) tcp state bypass will be required on the firewall&lt;/P&gt;&lt;P&gt;4) UDP traffic will get dropped due to assymeteric routing, so we will require a local DNS server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another option is to utilize 2 ISPs on the PIX on 2 different interfaces. Configure 2 interfaces say out1 &amp;amp; out2 at security level 0. One will be for internet and other will be for IPSec tunnel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps. Please reply back if you need any further assistance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Chirag&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;P.S.: Please mark this thread as answered if you feel your query is answered. Do rate helpful posts.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Mar 2011 14:43:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-routing-issue-in-pix501/m-p/1596423#M559958</guid>
      <dc:creator>csaxena</dc:creator>
      <dc:date>2011-03-15T14:43:42Z</dc:date>
    </item>
    <item>
      <title>Re: Strange routing issue in PIX501</title>
      <link>https://community.cisco.com/t5/network-security/strange-routing-issue-in-pix501/m-p/1596424#M559960</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Saxena,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your reply and support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think my firewall PIX 501 does not support tcp state bypass configuration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;your second option is also difficult to opt as i have only two interfaces of cisco PIX 501 ( inside and outside)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What about if you use Layer 3 switch&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any other option to stream line routing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lokking forward for your support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Mar 2011 03:56:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-routing-issue-in-pix501/m-p/1596424#M559960</guid>
      <dc:creator>imranbhatti151</dc:creator>
      <dc:date>2011-03-16T03:56:32Z</dc:date>
    </item>
    <item>
      <title>Re: Strange routing issue in PIX501</title>
      <link>https://community.cisco.com/t5/network-security/strange-routing-issue-in-pix501/m-p/1596425#M559963</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes on a layer 3 switch you can do routing for internet &amp;amp; corp network. This will help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Chirag&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Mar 2011 04:41:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-routing-issue-in-pix501/m-p/1596425#M559963</guid>
      <dc:creator>csaxena</dc:creator>
      <dc:date>2011-03-16T04:41:41Z</dc:date>
    </item>
    <item>
      <title>Re: Strange routing issue in PIX501</title>
      <link>https://community.cisco.com/t5/network-security/strange-routing-issue-in-pix501/m-p/1596426#M559964</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Again,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems that i do not have any Layer 3 switch in inventory now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can i set it up using router 1900 series with two ethernet interfaces.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Making three vlans and then inter vlan routing.&lt;/P&gt;&lt;P&gt;Please suggest.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Mar 2011 05:29:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-routing-issue-in-pix501/m-p/1596426#M559964</guid>
      <dc:creator>imranbhatti151</dc:creator>
      <dc:date>2011-03-16T05:29:24Z</dc:date>
    </item>
  </channel>
</rss>

