<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Basic Pix config not working. Can anyone help!??!! in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/basic-pix-config-not-working-can-anyone-help/m-p/185051#M605656</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your subnet mask on your outside interface and global pool is wrong. 255.255.255.19 is not an acceptible mask. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Even if you meant 255.255.255.192, it won't work because your route outside statement doesn't point to a host in the same subnet as the external interface. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is 210.44.136.1 your route to the internet? Do you have the full class C of 210.44.136.0 ? If so, 255.255.255.0 is the subnet mask you should use&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 22 May 2003 18:45:18 GMT</pubDate>
    <dc:creator>mostiguy</dc:creator>
    <dc:date>2003-05-22T18:45:18Z</dc:date>
    <item>
      <title>Basic Pix config not working. Can anyone help!??!!</title>
      <link>https://community.cisco.com/t5/network-security/basic-pix-config-not-working-can-anyone-help/m-p/185050#M605654</link>
      <description>&lt;P&gt;--begin ciscomoderator note-- The following post has been edited to remove potentially confidential information. Please refrain from posting confidential information on the site to reduce security risks to your network. -- end ciscomoderator note -- &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the config. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0 &lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100 &lt;/P&gt;&lt;P&gt;enable password XXXXXXXXX encrypted &lt;/P&gt;&lt;P&gt;passwd XXXXXXXXX encrypted &lt;/P&gt;&lt;P&gt;hostname pixfirewall &lt;/P&gt;&lt;P&gt;fixup protocol ftp 21 &lt;/P&gt;&lt;P&gt;fixup protocol http 80 &lt;/P&gt;&lt;P&gt;fixup protocol h323 1720 &lt;/P&gt;&lt;P&gt;fixup protocol rsh 514 &lt;/P&gt;&lt;P&gt;fixup protocol smtp 25 &lt;/P&gt;&lt;P&gt;fixup protocol sqlnet 1521 &lt;/P&gt;&lt;P&gt;fixup protocol sip 5060 &lt;/P&gt;&lt;P&gt;names &lt;/P&gt;&lt;P&gt;pager lines 24 &lt;/P&gt;&lt;P&gt;logging on &lt;/P&gt;&lt;P&gt;no logging timestamp &lt;/P&gt;&lt;P&gt;no logging standby &lt;/P&gt;&lt;P&gt;no logging console &lt;/P&gt;&lt;P&gt;no logging monitor &lt;/P&gt;&lt;P&gt;no logging buffered &lt;/P&gt;&lt;P&gt;no logging trap &lt;/P&gt;&lt;P&gt;no logging history &lt;/P&gt;&lt;P&gt;logging facility 20 &lt;/P&gt;&lt;P&gt;logging queue 512 &lt;/P&gt;&lt;P&gt;interface ethernet0 10baset &lt;/P&gt;&lt;P&gt;interface ethernet1 10baset &lt;/P&gt;&lt;P&gt;mtu outside 1500 &lt;/P&gt;&lt;P&gt;mtu inside 1500 &lt;/P&gt;&lt;P&gt;ip address outside nnn.nn.nnn.199 255.255.255.19 &lt;/P&gt;&lt;P&gt;ip address inside 192.168.121.2 255.255.255.0 &lt;/P&gt;&lt;P&gt;ip audit info action alarm &lt;/P&gt;&lt;P&gt;ip audit attack action alarm &lt;/P&gt;&lt;P&gt;arp timeout 14400 &lt;/P&gt;&lt;P&gt;global (outside) 1 nnn.nn.nnn.230-nnn.nn.nnn.232 netmask 255.255.255.19 &lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0 &lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 nnn.nn.nnn.1 1 &lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00 &lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h323 0:05:00 si &lt;/P&gt;&lt;P&gt;p 0:30:00 sip_media 0:02:00 &lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute &lt;/P&gt;&lt;P&gt;aaa-server TACACS+ protocol tacacs+ &lt;/P&gt;&lt;P&gt;aaa-server RADIUS protocol radius &lt;/P&gt;&lt;P&gt;no snmp-server location &lt;/P&gt;&lt;P&gt;no snmp-server contact &lt;/P&gt;&lt;P&gt;snmp-server community public &lt;/P&gt;&lt;P&gt;no snmp-server enable traps &lt;/P&gt;&lt;P&gt;floodguard enable &lt;/P&gt;&lt;P&gt;no sysopt route dnat &lt;/P&gt;&lt;P&gt;isakmp identity address &lt;/P&gt;&lt;P&gt;telnet timeout 5 &lt;/P&gt;&lt;P&gt;ssh timeout 5 &lt;/P&gt;&lt;P&gt;terminal width 80 &lt;/P&gt;&lt;P&gt;Cryptochecksum: &lt;/P&gt;&lt;P&gt;: end &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 06:45:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-pix-config-not-working-can-anyone-help/m-p/185050#M605654</guid>
      <dc:creator>ddevecka</dc:creator>
      <dc:date>2020-02-21T06:45:34Z</dc:date>
    </item>
    <item>
      <title>Re: Basic Pix config not working. Can anyone help!??!!</title>
      <link>https://community.cisco.com/t5/network-security/basic-pix-config-not-working-can-anyone-help/m-p/185051#M605656</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your subnet mask on your outside interface and global pool is wrong. 255.255.255.19 is not an acceptible mask. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Even if you meant 255.255.255.192, it won't work because your route outside statement doesn't point to a host in the same subnet as the external interface. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is 210.44.136.1 your route to the internet? Do you have the full class C of 210.44.136.0 ? If so, 255.255.255.0 is the subnet mask you should use&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 May 2003 18:45:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-pix-config-not-working-can-anyone-help/m-p/185051#M605656</guid>
      <dc:creator>mostiguy</dc:creator>
      <dc:date>2003-05-22T18:45:18Z</dc:date>
    </item>
    <item>
      <title>Re: Basic Pix config not working. Can anyone help!??!!</title>
      <link>https://community.cisco.com/t5/network-security/basic-pix-config-not-working-can-anyone-help/m-p/185052#M605657</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you say not working - what is not working?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't see a problem with your configuration.  When you say it is not working, is it that the internal users are not able to connect to the Internet (outside)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It could be as simple as this:  your inside interface is x.x.x.2 , usually it is set as x.x.x.1 - so either you have one more device with x.x.x.1 and hence the issue is not with the PIX at all OR simply it is a type and hence change this inside IP to x.x.x.1 or change the default gateway on the inside hosts to x.x.x.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hope this helps&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards / Sampath.&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:Srengarajan@att.com"&gt;Srengarajan@att.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 May 2003 15:13:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-pix-config-not-working-can-anyone-help/m-p/185052#M605657</guid>
      <dc:creator>sampathsr</dc:creator>
      <dc:date>2003-05-27T15:13:27Z</dc:date>
    </item>
    <item>
      <title>Re: Basic Pix config not working. Can anyone help!??!!</title>
      <link>https://community.cisco.com/t5/network-security/basic-pix-config-not-working-can-anyone-help/m-p/185053#M605658</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is no route statement for return traffic. You have to give &lt;/P&gt;&lt;P&gt;route inside command so that the outside traffic can reach your inside network (only allowed).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Deepu&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 May 2003 16:49:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-pix-config-not-working-can-anyone-help/m-p/185053#M605658</guid>
      <dc:creator>dnagarajachary</dc:creator>
      <dc:date>2003-05-27T16:49:32Z</dc:date>
    </item>
    <item>
      <title>Re: Basic Pix config not working. Can anyone help!??!!</title>
      <link>https://community.cisco.com/t5/network-security/basic-pix-config-not-working-can-anyone-help/m-p/185054#M605659</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Not true.  If the traffic is only originatting from the inside to the outside, then only a route outside statement would suffice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. If you are using the PIX as a DHCP client to 'pick-up' a dynamic IP address on the outside interface (such as when the PIX connecting to a cable-modem), you don't even need an explicit route outside statement; instead you could just say:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip address outside dhcp setroute&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this clarifies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards / Sampath.&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:Srengarajan@att.com"&gt;Srengarajan@att.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 May 2003 17:38:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-pix-config-not-working-can-anyone-help/m-p/185054#M605659</guid>
      <dc:creator>sampathsr</dc:creator>
      <dc:date>2003-05-27T17:38:48Z</dc:date>
    </item>
    <item>
      <title>Re: Basic Pix config not working. Can anyone help!??!!</title>
      <link>https://community.cisco.com/t5/network-security/basic-pix-config-not-working-can-anyone-help/m-p/185055#M605660</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;PIX cannot do routing by default. It needs to be told where to send the packets &amp;amp; from what interface.Your internal network 192.168.121.0/24 needs to be specified using the route inside statement in your config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Feb 2004 23:22:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-pix-config-not-working-can-anyone-help/m-p/185055#M605660</guid>
      <dc:creator>rahil.patel</dc:creator>
      <dc:date>2004-02-06T23:22:31Z</dc:date>
    </item>
    <item>
      <title>Re: Basic Pix config not working. Can anyone help!??!!</title>
      <link>https://community.cisco.com/t5/network-security/basic-pix-config-not-working-can-anyone-help/m-p/185056#M605661</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Actually the PIX "WILL" route to every subnet it is apart of (just like a router). You may not see it in the config but if you issue the command show route, you will see it as connected vice static. Also, to the person who posted this, you must give us more information on what your problem is. Do you have zero connectivity through the PIX? If so, I see you didnt post the top lines of the config. By default, the interfaces of a PIX are shutdown, you must issue the interface ethernet0 auto (or whatever the interface is and speed/duplex you want) to "unshut" the interface. If you have some connectivity, let us know what the deal is. Can you surf web? What kind of connection do you have out? A static IP through an ISP or is this a home cable/dsl connection that provides you DHCP? Can you ping from the pix to inside and pix to outside? We need more info to help you out.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 07 Feb 2004 02:51:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-pix-config-not-working-can-anyone-help/m-p/185056#M605661</guid>
      <dc:creator>baileja</dc:creator>
      <dc:date>2004-02-07T02:51:34Z</dc:date>
    </item>
    <item>
      <title>Re: Basic Pix config not working. Can anyone help!??!!</title>
      <link>https://community.cisco.com/t5/network-security/basic-pix-config-not-working-can-anyone-help/m-p/185057#M605662</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The documentation clearly says that the PIX is NOT a router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is not routing to send a packet to a connected interface. Any host will do that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The mask on the outside interface and the global statement that references it is bad.  Other than that please describe the problem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 07 Feb 2004 03:46:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-pix-config-not-working-can-anyone-help/m-p/185057#M605662</guid>
      <dc:creator>rjackson</dc:creator>
      <dc:date>2004-02-07T03:46:49Z</dc:date>
    </item>
    <item>
      <title>Re: Basic Pix config not working. Can anyone help!??!!</title>
      <link>https://community.cisco.com/t5/network-security/basic-pix-config-not-working-can-anyone-help/m-p/185058#M605663</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are correct in saying the PIX is not a router. But by specifying an ip address on the inside, and an IP address on the outside, you do not need to add the "Route" command to get packets from outside to in. The PIX will do this on its own. I have about 6 PIX's doing this now. And I think the mask provided in the config above is a typo. I dont believe the PIX will accept this argument.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 08 Feb 2004 06:23:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-pix-config-not-working-can-anyone-help/m-p/185058#M605663</guid>
      <dc:creator>baileja</dc:creator>
      <dc:date>2004-02-08T06:23:31Z</dc:date>
    </item>
  </channel>
</rss>

