<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX with two interfaces with security0 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-with-two-interfaces-with-security0/m-p/263863#M594045</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Having 2 interfaces with the same security level is an unsupported configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why do you want two interfaces to respond the same way? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 12 Mar 2004 12:39:50 GMT</pubDate>
    <dc:creator>mostiguy</dc:creator>
    <dc:date>2004-03-12T12:39:50Z</dc:date>
    <item>
      <title>PIX with two interfaces with security0</title>
      <link>https://community.cisco.com/t5/network-security/pix-with-two-interfaces-with-security0/m-p/263862#M594044</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A customer have a PIX 515E with two interfaces with security0 (ethernet0 and ethernet4 for example).&lt;/P&gt;&lt;P&gt;How can we have this PIX having those 2 interfaces the same way to response to TCP packet asking to open a not-open-port on those 2 PIX interfaces ?&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;I would like the ethernet4 having the same to respond when receiving a TCP SYN packet for TCP port as 25, or 23.&lt;/P&gt;&lt;P&gt;The destination IP address is the one of the ethernet4 interface, and the destination TCP port isn't opened.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a link with all difference between ethernet0 and any other interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can we use any non-ethernet0 interface with security0 to be used as the outside world ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your explaination and links.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:17:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-with-two-interfaces-with-security0/m-p/263862#M594044</guid>
      <dc:creator>jabouaf</dc:creator>
      <dc:date>2020-02-21T07:17:23Z</dc:date>
    </item>
    <item>
      <title>Re: PIX with two interfaces with security0</title>
      <link>https://community.cisco.com/t5/network-security/pix-with-two-interfaces-with-security0/m-p/263863#M594045</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Having 2 interfaces with the same security level is an unsupported configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why do you want two interfaces to respond the same way? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Mar 2004 12:39:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-with-two-interfaces-with-security0/m-p/263863#M594045</guid>
      <dc:creator>mostiguy</dc:creator>
      <dc:date>2004-03-12T12:39:50Z</dc:date>
    </item>
    <item>
      <title>Re: PIX with two interfaces with security0</title>
      <link>https://community.cisco.com/t5/network-security/pix-with-two-interfaces-with-security0/m-p/263864#M594046</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well I think that:&lt;/P&gt;&lt;P&gt;One way to have no communication between two interfaces can be done by giving them the same security level. Traffic can go from securityA interface to security(A-1) interface without doing anything. &lt;/P&gt;&lt;P&gt;Communication is only possible between a lower to a higger or a higger to a lower security level.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MAybe I'm wrong, so if you can argu, this could help me.&lt;/P&gt;&lt;P&gt;Do you have any link about that two interfaces can NOT have the same security level ? Maybe I m bad thinking that it is possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX release 6.3.3 on a PIX515E with 6 interfaces do accept the commandes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway, two interfaces having the same configuration should act the same way to any same packets received. This is right for a router !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway, we could have two providers links on the same PIX. In fact I do not know yet why the customer uses 2 interfaces as "ouside world", but the sniffer traces show me that those two interfaces do not response the same way when receiving a telnet initiation packet for example TCP port 25 or 23.&lt;/P&gt;&lt;P&gt;The less then basic configuration is the same. I just move the IP address and the "outside" cable form one interface to the other one.&lt;/P&gt;&lt;P&gt;No command with an explicite interface name, excepted a SSH permit command (to reach the PIX from an outside link).&lt;/P&gt;&lt;P&gt;So only port 22 is opened on those two interfaces.&lt;/P&gt;&lt;P&gt;  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Mar 2004 13:19:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-with-two-interfaces-with-security0/m-p/263864#M594046</guid>
      <dc:creator>jabouaf</dc:creator>
      <dc:date>2004-03-12T13:19:11Z</dc:date>
    </item>
  </channel>
</rss>

