<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Intra-interface traffic in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/intra-interface-traffic/m-p/1271052#M816453</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Stefano,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The PIX will not act as a router, it will not accept traffic from and interface and route is back out of the same interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 21 Oct 2009 08:06:00 GMT</pubDate>
    <dc:creator>andrew.prince</dc:creator>
    <dc:date>2009-10-21T08:06:00Z</dc:date>
    <item>
      <title>Intra-interface traffic</title>
      <link>https://community.cisco.com/t5/network-security/intra-interface-traffic/m-p/1271051#M816443</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;  I have a customer which has a PIX 6.x .&lt;/P&gt;&lt;P&gt;We added an internal network behind another router .&lt;/P&gt;&lt;P&gt;  Clients have the pix as DG , and we wish not to chage it .&lt;/P&gt;&lt;P&gt;  We've added routing info on the pix and set the PIX as DG of the additional router .&lt;/P&gt;&lt;P&gt;  We know that by default pix does not route on the same interface and that on PIX7.x the command &lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt; can be used to solve the issue .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'd like to know if it would work on Pix 6.x as well or if we have to update it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks &lt;/P&gt;&lt;P&gt;Stefano&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:28:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/intra-interface-traffic/m-p/1271051#M816443</guid>
      <dc:creator>s_colombo</dc:creator>
      <dc:date>2019-03-11T16:28:30Z</dc:date>
    </item>
    <item>
      <title>Re: Intra-interface traffic</title>
      <link>https://community.cisco.com/t5/network-security/intra-interface-traffic/m-p/1271052#M816453</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Stefano,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The PIX will not act as a router, it will not accept traffic from and interface and route is back out of the same interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Oct 2009 08:06:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/intra-interface-traffic/m-p/1271052#M816453</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-10-21T08:06:00Z</dc:date>
    </item>
    <item>
      <title>Re: Intra-interface traffic</title>
      <link>https://community.cisco.com/t5/network-security/intra-interface-traffic/m-p/1271053#M816462</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Andrew &lt;/P&gt;&lt;P&gt;I found this doc which seems related to my environment&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a0080734db7.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a0080734db7.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Oct 2009 08:41:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/intra-interface-traffic/m-p/1271053#M816462</guid>
      <dc:creator>s_colombo</dc:creator>
      <dc:date>2009-10-21T08:41:18Z</dc:date>
    </item>
    <item>
      <title>Re: Intra-interface traffic</title>
      <link>https://community.cisco.com/t5/network-security/intra-interface-traffic/m-p/1271054#M816484</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes - my error, I did not read in your original post the other ip subnet was behind another router - my mistake.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Re-reading your post again, no the option for inter-interface communication is not available on code 6.3(x) you need to upgrade to either 7.x or 8.x for that functionality.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry for the confusion.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Oct 2009 10:39:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/intra-interface-traffic/m-p/1271054#M816484</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-10-21T10:39:04Z</dc:date>
    </item>
    <item>
      <title>Re: Intra-interface traffic</title>
      <link>https://community.cisco.com/t5/network-security/intra-interface-traffic/m-p/1271055#M816503</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As the other poster mentioned, this is not possible on Pix 6. Even in Pix 7/8 with "same-security-traffic permit intra-interface" you still need to make sure that the return traffic is also routed through the Pix, so you'll need to do some fancy NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You mentioned that "Clients have the pix as DG , and we wish not to chage it". Do you mean that you want the traffic to be firewalled (in that case, consider adding an interface to the Pix) or that you do not want to re-configure all the clients? In the latter case, you could simply swap the ip addresses of the router and the Pix?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Oct 2009 13:01:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/intra-interface-traffic/m-p/1271055#M816503</guid>
      <dc:creator>Herbert Baerten</dc:creator>
      <dc:date>2009-10-21T13:01:09Z</dc:date>
    </item>
  </channel>
</rss>

