<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sending OSPF Routes Through a PIX in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/sending-ospf-routes-through-a-pix/m-p/265489#M593310</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have a read of the following document:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/tech/tk583/tk372/technologies_configuration_example09186a00800a43f6.shtml" target="_blank"&gt;http://www.cisco.com/en/US/tech/tk583/tk372/technologies_configuration_example09186a00800a43f6.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jay&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 15 Apr 2004 13:38:32 GMT</pubDate>
    <dc:creator>jmia</dc:creator>
    <dc:date>2004-04-15T13:38:32Z</dc:date>
    <item>
      <title>Sending OSPF Routes Through a PIX</title>
      <link>https://community.cisco.com/t5/network-security/sending-ospf-routes-through-a-pix/m-p/265487#M593303</link>
      <description>&lt;P&gt;We're looking at using an Internet VPN as a backup connection between 2 data centers.  To handle this dynamically, we'd like to put a router in a DMZ of our PIX 525s and have it share OSPF tables with a router on the inside network from the PIX.  Anotherwords, our 6509s make a policy based routing decision on whether or not to send traffic out the private MPLS network, or, they send it to the DMZ VPN router to travel across a VPN to its destination.  I'm having trouble finding documentation on how to do this, can anyone assist?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:20:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sending-ospf-routes-through-a-pix/m-p/265487#M593303</guid>
      <dc:creator>admin_2</dc:creator>
      <dc:date>2020-02-21T07:20:51Z</dc:date>
    </item>
    <item>
      <title>Re: Sending OSPF Routes Through a PIX</title>
      <link>https://community.cisco.com/t5/network-security/sending-ospf-routes-through-a-pix/m-p/265488#M593305</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you do not want the pix firewalls to process the ospf updates, instead just forwarding them between your internal and dmz routers, this is called sending ospf thru the pix (instead of to it).  This can be done only if you configure gre tunnels or ipsec tunnels between your internal and dmz routers.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When configure acls on all of the pixes to allow the gre or ipsec traffic, you need add the rules on both the internal and dmz interfaces of each pix that will see the traffic.  This is because you cannot determine which router (dmz or internal) will send the updates first.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to use ipsec, the relevant acls would include udp src port 500 to dest port 500, the ah and the esp protocols.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For gre, just spec the gre protocol instead of tcp/udp.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Again the connection can originate on either end so you will need the same rules (with source and dest reversed) on the dmz side as well as the internal side.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if you have any questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Apr 2004 13:32:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sending-ospf-routes-through-a-pix/m-p/265488#M593305</guid>
      <dc:creator>ehirsel</dc:creator>
      <dc:date>2004-04-15T13:32:53Z</dc:date>
    </item>
    <item>
      <title>Re: Sending OSPF Routes Through a PIX</title>
      <link>https://community.cisco.com/t5/network-security/sending-ospf-routes-through-a-pix/m-p/265489#M593310</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have a read of the following document:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/tech/tk583/tk372/technologies_configuration_example09186a00800a43f6.shtml" target="_blank"&gt;http://www.cisco.com/en/US/tech/tk583/tk372/technologies_configuration_example09186a00800a43f6.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jay&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Apr 2004 13:38:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sending-ospf-routes-through-a-pix/m-p/265489#M593310</guid>
      <dc:creator>jmia</dc:creator>
      <dc:date>2004-04-15T13:38:32Z</dc:date>
    </item>
  </channel>
</rss>

