<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ospf in the pix in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ospf-in-the-pix/m-p/214903#M610070</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; We have pix 506 (location A) with ver 6.3(1) vpn lan to lan to the concentrator 3015 (location B). If I have other vpn route ( in the location C) make lan to lan to the PIX 506 (location A), could I enable OSPF in the PIX 506, routing location C traffic to the location B? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ben&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 07:32:49 GMT</pubDate>
    <dc:creator>bma</dc:creator>
    <dc:date>2020-02-21T07:32:49Z</dc:date>
    <item>
      <title>ospf in the pix</title>
      <link>https://community.cisco.com/t5/network-security/ospf-in-the-pix/m-p/214903#M610070</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; We have pix 506 (location A) with ver 6.3(1) vpn lan to lan to the concentrator 3015 (location B). If I have other vpn route ( in the location C) make lan to lan to the PIX 506 (location A), could I enable OSPF in the PIX 506, routing location C traffic to the location B? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ben&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:32:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ospf-in-the-pix/m-p/214903#M610070</guid>
      <dc:creator>bma</dc:creator>
      <dc:date>2020-02-21T07:32:49Z</dc:date>
    </item>
    <item>
      <title>Re: ospf in the pix</title>
      <link>https://community.cisco.com/t5/network-security/ospf-in-the-pix/m-p/214904#M610071</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't think that can be done.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When defining crypto ACL on the the 506, what traffic are you going to define as interesting? You can't define a crypto ACL for PIX's outside interface sourcing OSPF traffic. Also, OSPF uses multicast traffic to establish neighbor adjacency, and since the neighbor command is not available on the PIX, you't can't statically configure a neighbor to pass unicast update. IPSec will not pass multicast traffic, only GRE could.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The biggest hurdle is that PIX simply won't send traffic out the same interface it receives from, VPN or not. Thus, you can't pass traffic to the PIX and ask it to redirect that traffic out to the Concentrator.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Aug 2004 08:06:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ospf-in-the-pix/m-p/214904#M610071</guid>
      <dc:creator>dtangent</dc:creator>
      <dc:date>2004-08-05T08:06:02Z</dc:date>
    </item>
  </channel>
</rss>

