<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PIX 535 connectivity issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-535-connectivity-issue/m-p/79307#M626397</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have pix 535 with 6.2(2). I have the inside with address as 172.20.10.0/24, with 172.20.10.1 as the pix interface. One of the DMZ's that is DMZ-corporate, with network 172.20.30.0/24, and 172.20.30.1 as the pix interface address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured the route command, the output of show route&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;idcm-p535-mnpr# sh route&lt;/P&gt;&lt;P&gt;        outside 0.0.0.0 0.0.0.0 200.90.134.2 1 OTHER static&lt;/P&gt;&lt;P&gt;        FailOver 172.10.9.0 255.255.255.252 172.10.9.1 1 CONNECT static&lt;/P&gt;&lt;P&gt;        DMZ-Mon 172.16.15.0 255.255.255.0 172.16.15.1 1 CONNECT static&lt;/P&gt;&lt;P&gt;        DMZ-Mon 172.16.16.0 255.255.255.0 172.16.15.5 1 OTHER static&lt;/P&gt;&lt;P&gt;        inside 172.20.10.0 255.255.255.0 172.20.10.1 1 CONNECT static&lt;/P&gt;&lt;P&gt;        inside NOC-Operators 255.255.255.0 172.20.10.2 1 OTHER static&lt;/P&gt;&lt;P&gt;        DMZ-Signaling 172.20.19.0 255.255.255.0 172.20.20.2 1 OTHER static&lt;/P&gt;&lt;P&gt;        DMZ-Signaling 172.20.20.0 255.255.255.0 172.20.20.1 1 CONNECT static&lt;/P&gt;&lt;P&gt;        DMZ-Corporate 172.20.30.0 255.255.255.0 172.20.30.1 1 CONNECT static&lt;/P&gt;&lt;P&gt;        DMZ-Collocation 200.90.128.0 255.255.255.0 200.90.128.1 1 CONNECT static&lt;/P&gt;&lt;P&gt;        DMZ-TCI-Services 200.90.132.0 255.255.255.0 200.90.132.1 1 CONNECT static&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not able to communicate either from 172.20.10.0 network to 172.20.30.0 n/w or vise versa. &lt;/P&gt;&lt;P&gt;What am I missing. I have the pix as the default gateway on the devices in the respective networks.&lt;/P&gt;&lt;P&gt;Appreciate comments.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Habib&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 06:21:51 GMT</pubDate>
    <dc:creator>habibd</dc:creator>
    <dc:date>2020-02-21T06:21:51Z</dc:date>
    <item>
      <title>PIX 535 connectivity issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-535-connectivity-issue/m-p/79307#M626397</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have pix 535 with 6.2(2). I have the inside with address as 172.20.10.0/24, with 172.20.10.1 as the pix interface. One of the DMZ's that is DMZ-corporate, with network 172.20.30.0/24, and 172.20.30.1 as the pix interface address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured the route command, the output of show route&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;idcm-p535-mnpr# sh route&lt;/P&gt;&lt;P&gt;        outside 0.0.0.0 0.0.0.0 200.90.134.2 1 OTHER static&lt;/P&gt;&lt;P&gt;        FailOver 172.10.9.0 255.255.255.252 172.10.9.1 1 CONNECT static&lt;/P&gt;&lt;P&gt;        DMZ-Mon 172.16.15.0 255.255.255.0 172.16.15.1 1 CONNECT static&lt;/P&gt;&lt;P&gt;        DMZ-Mon 172.16.16.0 255.255.255.0 172.16.15.5 1 OTHER static&lt;/P&gt;&lt;P&gt;        inside 172.20.10.0 255.255.255.0 172.20.10.1 1 CONNECT static&lt;/P&gt;&lt;P&gt;        inside NOC-Operators 255.255.255.0 172.20.10.2 1 OTHER static&lt;/P&gt;&lt;P&gt;        DMZ-Signaling 172.20.19.0 255.255.255.0 172.20.20.2 1 OTHER static&lt;/P&gt;&lt;P&gt;        DMZ-Signaling 172.20.20.0 255.255.255.0 172.20.20.1 1 CONNECT static&lt;/P&gt;&lt;P&gt;        DMZ-Corporate 172.20.30.0 255.255.255.0 172.20.30.1 1 CONNECT static&lt;/P&gt;&lt;P&gt;        DMZ-Collocation 200.90.128.0 255.255.255.0 200.90.128.1 1 CONNECT static&lt;/P&gt;&lt;P&gt;        DMZ-TCI-Services 200.90.132.0 255.255.255.0 200.90.132.1 1 CONNECT static&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not able to communicate either from 172.20.10.0 network to 172.20.30.0 n/w or vise versa. &lt;/P&gt;&lt;P&gt;What am I missing. I have the pix as the default gateway on the devices in the respective networks.&lt;/P&gt;&lt;P&gt;Appreciate comments.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Habib&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 06:21:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-535-connectivity-issue/m-p/79307#M626397</guid>
      <dc:creator>habibd</dc:creator>
      <dc:date>2020-02-21T06:21:51Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 535 connectivity issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-535-connectivity-issue/m-p/79308#M626399</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To enable connectivity from inside to dmz, you also need to have nat (inside) and global (dmz) commands configured. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/warp/public/707/28.html#topic1" target="_blank"&gt;http://www.cisco.com/warp/public/707/28.html#topic1&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hope this helps, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~Nairi &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Nov 2002 00:04:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-535-connectivity-issue/m-p/79308#M626399</guid>
      <dc:creator>Nairi Adamian</dc:creator>
      <dc:date>2002-11-11T00:04:32Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 535 connectivity issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-535-connectivity-issue/m-p/79309#M626401</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Nairi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the info.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One clarification, so to communicate from a higher security to a lower security interface you require NAT. And for Communicating from lower security to higher security interface you require some sort of translation. This translation is it only static translation only or I can use something else.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What my concern is, I was thinking that if I have a route on the PIX to various network and when a packet comes from one network to go to the other, the routes are not enough and you require some translation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Appreciate your clarification.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Habib Dashti&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Nov 2002 14:47:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-535-connectivity-issue/m-p/79309#M626401</guid>
      <dc:creator>habibd</dc:creator>
      <dc:date>2002-11-11T14:47:12Z</dc:date>
    </item>
  </channel>
</rss>

