<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Back-to-back PIX in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/back-to-back-pix/m-p/220368#M710069</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've setup the FWs, so internal users can access the Internet, DMZ and everything else. I've terminated the VPN on PIX1 and I'm able to connect from outside. However, I'm unable to get into my internal network. Do I need to add a route inside statement so that packets get forwarded from the PIX1 to the PIX2 inside interface. Perhaps, I need to add a static address? Does anyone have any ideas.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;JT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 14 Nov 2003 02:27:48 GMT</pubDate>
    <dc:creator>jtorkos</dc:creator>
    <dc:date>2003-11-14T02:27:48Z</dc:date>
    <item>
      <title>Back-to-back PIX</title>
      <link>https://community.cisco.com/t5/network-security/back-to-back-pix/m-p/220364#M709950</link>
      <description>&lt;P&gt;Does anyone know if this can work. I have two Pix 515 firewalls and the setup is as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISP - Router - PIX1 - PIX2 - Internal&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remote VPN users will terminate at PIX1 and I need to know how they will get to the internal network and how the internal users will get out to the Internet. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm thinking of setting up IPSEC between the firewalls, but do I need to configure "isakmp enable inside" on PIX1 and "isakmp enable outside" on PIX2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know if anyone has any ideas on this subject.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:06:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/back-to-back-pix/m-p/220364#M709950</guid>
      <dc:creator>jtorkos</dc:creator>
      <dc:date>2020-02-21T07:06:01Z</dc:date>
    </item>
    <item>
      <title>Re: Back-to-back PIX</title>
      <link>https://community.cisco.com/t5/network-security/back-to-back-pix/m-p/220365#M709959</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why would this setup not work? Why do you need IPSEC between PIX1 and PIX2. Just terminate VPN on PIX1 and allow the traffic for those IPs towards and from PIX2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For outbound traffic, simple NAT should work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Nadeem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Nov 2003 00:39:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/back-to-back-pix/m-p/220365#M709959</guid>
      <dc:creator>nkhawaja</dc:creator>
      <dc:date>2003-11-13T00:39:51Z</dc:date>
    </item>
    <item>
      <title>Re: Back-to-back PIX</title>
      <link>https://community.cisco.com/t5/network-security/back-to-back-pix/m-p/220366#M709994</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Wow, what a quick response. Just to understand what you have said. I create an ip pool for VPN users and create an access list that will forward the packets to PIX2. As for internal users, I just set up NAT and they should go out the Internet. I there a chance I can send you a diagram of how it looks like or is there a Cisco link that has a similiar example.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My home email address is &lt;A href="mailto:jtorkos@rogers.com"&gt;jtorkos@rogers.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Nov 2003 00:56:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/back-to-back-pix/m-p/220366#M709994</guid>
      <dc:creator>jtorkos</dc:creator>
      <dc:date>2003-11-13T00:56:31Z</dc:date>
    </item>
    <item>
      <title>Re: Back-to-back PIX</title>
      <link>https://community.cisco.com/t5/network-security/back-to-back-pix/m-p/220367#M710037</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can send me diagram at &lt;A href="mailto:nkhawaja@cisco.com"&gt;nkhawaja@cisco.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Nadeem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Nov 2003 05:26:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/back-to-back-pix/m-p/220367#M710037</guid>
      <dc:creator>nkhawaja</dc:creator>
      <dc:date>2003-11-13T05:26:35Z</dc:date>
    </item>
    <item>
      <title>Re: Back-to-back PIX</title>
      <link>https://community.cisco.com/t5/network-security/back-to-back-pix/m-p/220368#M710069</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've setup the FWs, so internal users can access the Internet, DMZ and everything else. I've terminated the VPN on PIX1 and I'm able to connect from outside. However, I'm unable to get into my internal network. Do I need to add a route inside statement so that packets get forwarded from the PIX1 to the PIX2 inside interface. Perhaps, I need to add a static address? Does anyone have any ideas.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;JT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Nov 2003 02:27:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/back-to-back-pix/m-p/220368#M710069</guid>
      <dc:creator>jtorkos</dc:creator>
      <dc:date>2003-11-14T02:27:48Z</dc:date>
    </item>
    <item>
      <title>Re: Back-to-back PIX</title>
      <link>https://community.cisco.com/t5/network-security/back-to-back-pix/m-p/220369#M710144</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You definitely need route statement for the inside network@PIX2 on PIX1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route inside &lt;INSIDE network=""&gt; &lt;MASK&gt; PIX2_outside_address&lt;/MASK&gt;&lt;/INSIDE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You also need the following on PIX2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static translation for inside network&lt;/P&gt;&lt;P&gt;access-list to allow the VPNIPs to come to the inside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Nadeem&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 15 Nov 2003 08:17:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/back-to-back-pix/m-p/220369#M710144</guid>
      <dc:creator>nkhawaja</dc:creator>
      <dc:date>2003-11-15T08:17:20Z</dc:date>
    </item>
    <item>
      <title>Re: Back-to-back PIX</title>
      <link>https://community.cisco.com/t5/network-security/back-to-back-pix/m-p/220370#M710217</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's working fine now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;JT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Nov 2003 14:11:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/back-to-back-pix/m-p/220370#M710217</guid>
      <dc:creator>jtorkos</dc:creator>
      <dc:date>2003-11-17T14:11:21Z</dc:date>
    </item>
  </channel>
</rss>

