<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: routing on pix in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/routing-on-pix/m-p/20922#M656076</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The reason this doesn't work is because the PIX will not send out ICMP redirects.  In your example you want your default gateway (10.10.10.10) to redirect the clients to 10.10.10.200 if they are destined for 172.16.0.0.  Routers don't actually "route" these packets in and back out the same interface, they send an ICMP redirect to the client and the client adds this route to its internal routing table.   From that point on the client talks directly to the 10.10.10.200 router.  The PIX will not do ICMP redirects on any port, therefore it can not be the default gateway on a subnet with multiple routers.  Just in case you wanted to know why.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 24 Apr 2002 13:30:38 GMT</pubDate>
    <dc:creator>jboyer</dc:creator>
    <dc:date>2002-04-24T13:30:38Z</dc:date>
    <item>
      <title>routing on pix</title>
      <link>https://community.cisco.com/t5/network-security/routing-on-pix/m-p/20919#M655909</link>
      <description>&lt;P&gt;Hi,my network has a default gateway, the inside interface of a pixfirewall.&lt;/P&gt;&lt;P&gt;There is  a workaround to permit  the pix to route traffic, incoming in its inside interface, vs a destination outbound the same interface???&lt;/P&gt;&lt;P&gt;e.g:   &lt;/P&gt;&lt;P&gt;the pakets come into inside are routed and sent outbound the inside:          &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip address inside 10.10.10.10 255.255.255.0          &lt;/P&gt;&lt;P&gt;route inside 172.16.0.0 255.255.0.0 10.10.10.200&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this is by default denied.&lt;/P&gt;&lt;P&gt;thank's in advance &lt;/P&gt;&lt;P&gt;Graziano&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 06:01:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-on-pix/m-p/20919#M655909</guid>
      <dc:creator>g.rodegari</dc:creator>
      <dc:date>2020-02-21T06:01:54Z</dc:date>
    </item>
    <item>
      <title>Re: routing on pix</title>
      <link>https://community.cisco.com/t5/network-security/routing-on-pix/m-p/20920#M655941</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The PIX does not act as a router. You may need to set the users default gateway to another router on your LAN  which can get to all your networks but which will forward external traffic (Internet etc) via the PIX. Alternatively, you could connect the other network to a different PIX interface. Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Apr 2002 08:18:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-on-pix/m-p/20920#M655941</guid>
      <dc:creator>johnbroadway</dc:creator>
      <dc:date>2002-04-19T08:18:10Z</dc:date>
    </item>
    <item>
      <title>Re: routing on pix</title>
      <link>https://community.cisco.com/t5/network-security/routing-on-pix/m-p/20921#M656021</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;Graziano&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Apr 2002 09:24:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-on-pix/m-p/20921#M656021</guid>
      <dc:creator>g.rodegari</dc:creator>
      <dc:date>2002-04-20T09:24:50Z</dc:date>
    </item>
    <item>
      <title>Re: routing on pix</title>
      <link>https://community.cisco.com/t5/network-security/routing-on-pix/m-p/20922#M656076</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The reason this doesn't work is because the PIX will not send out ICMP redirects.  In your example you want your default gateway (10.10.10.10) to redirect the clients to 10.10.10.200 if they are destined for 172.16.0.0.  Routers don't actually "route" these packets in and back out the same interface, they send an ICMP redirect to the client and the client adds this route to its internal routing table.   From that point on the client talks directly to the 10.10.10.200 router.  The PIX will not do ICMP redirects on any port, therefore it can not be the default gateway on a subnet with multiple routers.  Just in case you wanted to know why.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2002 13:30:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-on-pix/m-p/20922#M656076</guid>
      <dc:creator>jboyer</dc:creator>
      <dc:date>2002-04-24T13:30:38Z</dc:date>
    </item>
  </channel>
</rss>

