<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Pix + Broadband in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-broadband/m-p/169953#M602313</link>
    <description>&lt;P&gt;I've been researching this problem for several days now, and have come up totally short in terms of finding a solution. I have a PIX 515 with an internal network range of 10.10.0.0/8 behind it and a single external IP I obtain via DHCP [cable]. I have the PIX inside configured as 10.10.0.1 and I have it using DHCP to obtain an IP for the external address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now here's the problem: I can ping the other 10.10.0.0/8 machines&lt;/P&gt;&lt;P&gt;from the PIX, and I can ping outside IPs from the PIX. However, I cannot&lt;/P&gt;&lt;P&gt;get the traffic to route from the internal network through the PIX using&lt;/P&gt;&lt;P&gt;PAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think I am missing some route command to send all 0 0 traffic from the inside to the outside, but ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am still learning so any extra info would be appreciated as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX Version 6.2(2)                  &lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0                           &lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100                                   &lt;/P&gt;&lt;P&gt;enable password xxxxx&lt;/P&gt;&lt;P&gt;encrypted                                          &lt;/P&gt;&lt;P&gt;passwd xxxx&lt;/P&gt;&lt;P&gt; encrypted                                 &lt;/P&gt;&lt;P&gt;hostname test                &lt;/P&gt;&lt;P&gt;domain-name test                       &lt;/P&gt;&lt;P&gt;fixup protocol ftp 21                     &lt;/P&gt;&lt;P&gt;fixup protocol http 80                      &lt;/P&gt;&lt;P&gt;fixup protocol h323 h225 1720                             &lt;/P&gt;&lt;P&gt;fixup protocol h323 ras 1718-1719                                 &lt;/P&gt;&lt;P&gt;fixup protocol ils 389                      &lt;/P&gt;&lt;P&gt;fixup protocol rsh 514                      &lt;/P&gt;&lt;P&gt;fixup protocol rtsp 554                       &lt;/P&gt;&lt;P&gt;fixup protocol smtp 25                      &lt;/P&gt;&lt;P&gt;fixup protocol sqlnet 1521                          &lt;/P&gt;&lt;P&gt;fixup protocol sip 5060                       &lt;/P&gt;&lt;P&gt;fixup protocol skinny 2000                          &lt;/P&gt;&lt;P&gt;names     &lt;/P&gt;&lt;P&gt;access-list acl_grp permit icmp any any                                       &lt;/P&gt;&lt;P&gt;pager lines 24              &lt;/P&gt;&lt;P&gt;logging on          &lt;/P&gt;&lt;P&gt;logging buffered debugging                          &lt;/P&gt;&lt;P&gt;interface ethernet0 auto                        &lt;/P&gt;&lt;P&gt;interface ethernet1 auto                        &lt;/P&gt;&lt;P&gt;mtu outside 1500                &lt;/P&gt;&lt;P&gt;mtu inside 1500               &lt;/P&gt;&lt;P&gt;ip address outside dhcp setroute                                &lt;/P&gt;&lt;P&gt;ip address inside 10.10.0.1 255.0.0.0                                     &lt;/P&gt;&lt;P&gt;ip audit info action alarm                          &lt;/P&gt;&lt;P&gt;ip audit attack action alarm                            &lt;/P&gt;&lt;P&gt;pdm history enable                  &lt;/P&gt;&lt;P&gt;arp timeout 14400                 &lt;/P&gt;&lt;P&gt;global (outside) 1 interface                            &lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0                                  &lt;/P&gt;&lt;P&gt;conduit permit icmp any any&lt;/P&gt;&lt;P&gt;rip inside default version 1                               &lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00                     &lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h323 0:05:00 sip 0:30:00 sip_media 0:02:00                           &lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 a                     &lt;/P&gt;&lt;P&gt;aaa-server TACACS+ protocol tacacs+                                   &lt;/P&gt;&lt;P&gt;aaa-server RADIUS protocol radius                                 &lt;/P&gt;&lt;P&gt;aaa-server LOCAL protocol local                               &lt;/P&gt;&lt;P&gt;http server enable                  &lt;/P&gt;&lt;P&gt;http xxx.xxx.3.0 255.255.255.0 inside                                    &lt;/P&gt;&lt;P&gt;no snmp-server location                       &lt;/P&gt;&lt;P&gt;no snmp-server contact                      &lt;/P&gt;&lt;P&gt;snmp-server community public                            &lt;/P&gt;&lt;P&gt;no snmp-server enable traps                           &lt;/P&gt;&lt;P&gt;no floodguard enable&lt;/P&gt;&lt;P&gt;no sysopt route dnat&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;dhcpd address 10.10.0.10-10.10.0.50 inside&lt;/P&gt;&lt;P&gt;dhcpd lease 3000&lt;/P&gt;&lt;P&gt;dhcpd ping_timeout 750&lt;/P&gt;&lt;P&gt;dhcpd domain rw.com&lt;/P&gt;&lt;P&gt;dhcpd enable inside&lt;/P&gt;&lt;P&gt;terminal width 80&lt;/P&gt;&lt;P&gt;Cryptochecksum:&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 06:51:58 GMT</pubDate>
    <dc:creator>semaj9991</dc:creator>
    <dc:date>2020-02-21T06:51:58Z</dc:date>
    <item>
      <title>Pix + Broadband</title>
      <link>https://community.cisco.com/t5/network-security/pix-broadband/m-p/169953#M602313</link>
      <description>&lt;P&gt;I've been researching this problem for several days now, and have come up totally short in terms of finding a solution. I have a PIX 515 with an internal network range of 10.10.0.0/8 behind it and a single external IP I obtain via DHCP [cable]. I have the PIX inside configured as 10.10.0.1 and I have it using DHCP to obtain an IP for the external address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now here's the problem: I can ping the other 10.10.0.0/8 machines&lt;/P&gt;&lt;P&gt;from the PIX, and I can ping outside IPs from the PIX. However, I cannot&lt;/P&gt;&lt;P&gt;get the traffic to route from the internal network through the PIX using&lt;/P&gt;&lt;P&gt;PAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think I am missing some route command to send all 0 0 traffic from the inside to the outside, but ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am still learning so any extra info would be appreciated as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX Version 6.2(2)                  &lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0                           &lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100                                   &lt;/P&gt;&lt;P&gt;enable password xxxxx&lt;/P&gt;&lt;P&gt;encrypted                                          &lt;/P&gt;&lt;P&gt;passwd xxxx&lt;/P&gt;&lt;P&gt; encrypted                                 &lt;/P&gt;&lt;P&gt;hostname test                &lt;/P&gt;&lt;P&gt;domain-name test                       &lt;/P&gt;&lt;P&gt;fixup protocol ftp 21                     &lt;/P&gt;&lt;P&gt;fixup protocol http 80                      &lt;/P&gt;&lt;P&gt;fixup protocol h323 h225 1720                             &lt;/P&gt;&lt;P&gt;fixup protocol h323 ras 1718-1719                                 &lt;/P&gt;&lt;P&gt;fixup protocol ils 389                      &lt;/P&gt;&lt;P&gt;fixup protocol rsh 514                      &lt;/P&gt;&lt;P&gt;fixup protocol rtsp 554                       &lt;/P&gt;&lt;P&gt;fixup protocol smtp 25                      &lt;/P&gt;&lt;P&gt;fixup protocol sqlnet 1521                          &lt;/P&gt;&lt;P&gt;fixup protocol sip 5060                       &lt;/P&gt;&lt;P&gt;fixup protocol skinny 2000                          &lt;/P&gt;&lt;P&gt;names     &lt;/P&gt;&lt;P&gt;access-list acl_grp permit icmp any any                                       &lt;/P&gt;&lt;P&gt;pager lines 24              &lt;/P&gt;&lt;P&gt;logging on          &lt;/P&gt;&lt;P&gt;logging buffered debugging                          &lt;/P&gt;&lt;P&gt;interface ethernet0 auto                        &lt;/P&gt;&lt;P&gt;interface ethernet1 auto                        &lt;/P&gt;&lt;P&gt;mtu outside 1500                &lt;/P&gt;&lt;P&gt;mtu inside 1500               &lt;/P&gt;&lt;P&gt;ip address outside dhcp setroute                                &lt;/P&gt;&lt;P&gt;ip address inside 10.10.0.1 255.0.0.0                                     &lt;/P&gt;&lt;P&gt;ip audit info action alarm                          &lt;/P&gt;&lt;P&gt;ip audit attack action alarm                            &lt;/P&gt;&lt;P&gt;pdm history enable                  &lt;/P&gt;&lt;P&gt;arp timeout 14400                 &lt;/P&gt;&lt;P&gt;global (outside) 1 interface                            &lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0                                  &lt;/P&gt;&lt;P&gt;conduit permit icmp any any&lt;/P&gt;&lt;P&gt;rip inside default version 1                               &lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00                     &lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h323 0:05:00 sip 0:30:00 sip_media 0:02:00                           &lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 a                     &lt;/P&gt;&lt;P&gt;aaa-server TACACS+ protocol tacacs+                                   &lt;/P&gt;&lt;P&gt;aaa-server RADIUS protocol radius                                 &lt;/P&gt;&lt;P&gt;aaa-server LOCAL protocol local                               &lt;/P&gt;&lt;P&gt;http server enable                  &lt;/P&gt;&lt;P&gt;http xxx.xxx.3.0 255.255.255.0 inside                                    &lt;/P&gt;&lt;P&gt;no snmp-server location                       &lt;/P&gt;&lt;P&gt;no snmp-server contact                      &lt;/P&gt;&lt;P&gt;snmp-server community public                            &lt;/P&gt;&lt;P&gt;no snmp-server enable traps                           &lt;/P&gt;&lt;P&gt;no floodguard enable&lt;/P&gt;&lt;P&gt;no sysopt route dnat&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;dhcpd address 10.10.0.10-10.10.0.50 inside&lt;/P&gt;&lt;P&gt;dhcpd lease 3000&lt;/P&gt;&lt;P&gt;dhcpd ping_timeout 750&lt;/P&gt;&lt;P&gt;dhcpd domain rw.com&lt;/P&gt;&lt;P&gt;dhcpd enable inside&lt;/P&gt;&lt;P&gt;terminal width 80&lt;/P&gt;&lt;P&gt;Cryptochecksum:&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 06:51:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-broadband/m-p/169953#M602313</guid>
      <dc:creator>semaj9991</dc:creator>
      <dc:date>2020-02-21T06:51:58Z</dc:date>
    </item>
    <item>
      <title>Re: Pix + Broadband</title>
      <link>https://community.cisco.com/t5/network-security/pix-broadband/m-p/169954#M602314</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the default route is set by the 'setroute' parameter of the 'ip address' command. So that ok.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That nat/global statement also seem ok. Every packets that goes out is hidden by the outside interface address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are trying to mix conduits and access-lists. This may cause the problems. Remove the conduit command for the icmp and use only the access-list command. Make sure to bind the access-list to the outside interface:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no conduit permit icmp any any &lt;/P&gt;&lt;P&gt;access-list acl_grp permit icmp any any &lt;/P&gt;&lt;P&gt;access-group acl-grp in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These lines allow all inbound icmp traffic from the outside to the inside. May be you should narrow it down to only icmp echo replies packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind Regards,&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Jul 2003 14:47:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-broadband/m-p/169954#M602314</guid>
      <dc:creator>tvanginneken</dc:creator>
      <dc:date>2003-07-21T14:47:04Z</dc:date>
    </item>
  </channel>
</rss>

