<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Routing between a Pix and Internet Router in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/routing-between-a-pix-and-internet-router/m-p/53015#M623533</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, thanks for the info.  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 26 Sep 2002 23:07:40 GMT</pubDate>
    <dc:creator>r-remien</dc:creator>
    <dc:date>2002-09-26T23:07:40Z</dc:date>
    <item>
      <title>Routing between a Pix and Internet Router</title>
      <link>https://community.cisco.com/t5/network-security/routing-between-a-pix-and-internet-router/m-p/53013#M623531</link>
      <description>&lt;P&gt;Setup for outside VLAN:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.  Pix outside interface IP address 192.168.1.1&lt;/P&gt;&lt;P&gt;2.  Internet router e0/0 - 192.168.1.3&lt;/P&gt;&lt;P&gt;3.  default route on Pix - 0.0.0.0. 0.0.0.0 192.168.1.3&lt;/P&gt;&lt;P&gt;4.  default route on Internet router - 0.0.0.0. 0.0.0.0 &amp;lt;next hop to ISP&amp;gt;&lt;/P&gt;&lt;P&gt;I do not have a route that points to the Pix for Inbound traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2 questions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.  Without a route back to the Pix on my Internet router for inbound traffic, how does the router know how to send it to the Pix?&lt;/P&gt;&lt;P&gt;2.  Will this scenario work?&lt;/P&gt;&lt;P&gt;a.  Internet router - 192.168.1.3&lt;/P&gt;&lt;P&gt;b.  Outside Pix 1 interface - 192.168.1.1&lt;/P&gt;&lt;P&gt;c.  Outside Pix 2 interface - 192.168.1.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2 pix firewalls on the same outside subnet as my Internet router.  If I have a a 192.168.1.0/27 subnet and I have the following statics:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pix 1 - Static (inside,outside) 192.168.1.4 10.1.1.1 netmask 255.255.255.255 (Inside Lan 1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pix 2 - Static (inside,outside) 192.168.1.5 172.16.1.1 netmask 255.255.255.255 (Inside Lan 2)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to route two different static translations from the same subnet on the outside from the same Internet router to 2 different LANs behind 2 different Pixes?  If not, does anyone have another suggestion?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;RJ&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 06:16:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-between-a-pix-and-internet-router/m-p/53013#M623531</guid>
      <dc:creator>r-remien</dc:creator>
      <dc:date>2020-02-21T06:16:20Z</dc:date>
    </item>
    <item>
      <title>Re: Routing between a Pix and Internet Router</title>
      <link>https://community.cisco.com/t5/network-security/routing-between-a-pix-and-internet-router/m-p/53014#M623532</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1.  It will work if you are using NAT or a static map  for your internal IPs and the translated IP will be on the 192.168.1.x subnet (and then the router has that route -directly connectd).  If the NAT IP were on a different subnet, it would fail.&lt;/P&gt;&lt;P&gt;2.  Yes it is possible to have that scenario, as the 2 PIXs will only answer/translate to the IPs it knows about.  As long as the 2 PIXs don't have the same translation rules (both would answer for the same destination), you are fine.  They wouldn't know about each other or care.&lt;/P&gt;&lt;P&gt;An alternative to this, and one that increases redundancy, is to have the PIXs in failover and have all rules in the same place (downside is you need failover licence and more interfaces - 2 per subnet).&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Sep 2002 14:13:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-between-a-pix-and-internet-router/m-p/53014#M623532</guid>
      <dc:creator>steve.barlow</dc:creator>
      <dc:date>2002-09-26T14:13:53Z</dc:date>
    </item>
    <item>
      <title>Re: Routing between a Pix and Internet Router</title>
      <link>https://community.cisco.com/t5/network-security/routing-between-a-pix-and-internet-router/m-p/53015#M623533</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, thanks for the info.  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Sep 2002 23:07:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-between-a-pix-and-internet-router/m-p/53015#M623533</guid>
      <dc:creator>r-remien</dc:creator>
      <dc:date>2002-09-26T23:07:40Z</dc:date>
    </item>
  </channel>
</rss>

