<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help with Pix lab using sub interfaces in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/help-with-pix-lab-using-sub-interfaces/m-p/1166352#M860008</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;James&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If your 3550 is routing which it is why not set the default-gateway on your client to be the L3 vlan interface on the 3550 ie. 192.168.3.2 ? That would automatically allow you to ping 192.168.2.250 on the same switch. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As for pinging the other routers HQ &amp;amp; office then yes you will need to make them aware of 192.168.3.0/24 network. Easiset way to do this would be to configure RIP on the 3550. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The 3550 could still have the default-route set to 192.168.3.1 on the pix for any unknown ie. Internet addresses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a reason why the laptop has it's DG set to the pix rather than the 3550 ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 09 May 2009 21:12:24 GMT</pubDate>
    <dc:creator>Jon Marshall</dc:creator>
    <dc:date>2009-05-09T21:12:24Z</dc:date>
    <item>
      <title>Help with Pix lab using sub interfaces</title>
      <link>https://community.cisco.com/t5/network-security/help-with-pix-lab-using-sub-interfaces/m-p/1166349#M859999</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope you can spend a little of your time helping my fix this lab scenario.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What my goal is for my laptop on 192.168.3.20 (inside of pix) to be able to connect to 10.100.0.61/27 which is a loopback on my pretend New York router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the following equipment:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pix (HQ)&lt;/P&gt;&lt;P&gt;3550 (VLANs)&lt;/P&gt;&lt;P&gt;2 x 2620 routers (on VLAN 7 this my remote office link via serial back-to-back on RIPv2)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The 3550 is connect to the Pix on fas 0/1 and set as a trunk.  On the Pix I have setup Ethernet 2 as a sub-interface port.  I have created Ethernet 2.7 (192.168.2.1) for my VLAN 7 where my router is connected to (192.168.2.2).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I have working so far is the 2 routers via the serial link, RIPv2 is working and loopback 10.100.0.61 can ping 192.168.2.2 (routerhq), but not 192.168.2.1 (pix sub-int) on anthing on the inside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My laptop can ping 192.168.3.250 (3550 VLAN 2), but not any of the routers or the Pix sub-interface of 192.168.2.1.  &lt;/P&gt;&lt;P&gt;The problem I can't figure out is my inside LAN of 192.168.3.0/24 can't get to any of the routers or VLAN 7 it seems.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I put in some IP any any rules which didn't help and have checked the routes, and added some NAT exempts.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think I need a fresh pair of eyes as I'm sure I have confused myself somewhere.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:29:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-with-pix-lab-using-sub-interfaces/m-p/1166349#M859999</guid>
      <dc:creator>jamesgonzo</dc:creator>
      <dc:date>2019-03-11T15:29:37Z</dc:date>
    </item>
    <item>
      <title>Re: Help with Pix lab using sub interfaces</title>
      <link>https://community.cisco.com/t5/network-security/help-with-pix-lab-using-sub-interfaces/m-p/1166350#M860004</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;James&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you post &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) "sh ip route" from 2620 routers + 3550&lt;/P&gt;&lt;P&gt;2) "sh route" from pix.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you ping 3550 vlan 7 address 192.168.2.250 from office router ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 09 May 2009 20:14:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-with-pix-lab-using-sub-interfaces/m-p/1166350#M860004</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2009-05-09T20:14:46Z</dc:date>
    </item>
    <item>
      <title>Re: Help with Pix lab using sub interfaces</title>
      <link>https://community.cisco.com/t5/network-security/help-with-pix-lab-using-sub-interfaces/m-p/1166351#M860007</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for finding the time to help me here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Router_WAN_Office#&lt;/P&gt;&lt;P&gt;Gateway of last resort is not set&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;     172.16.0.0/30 is subnetted, 1 subnets&lt;/P&gt;&lt;P&gt;C       172.16.1.0 is directly connected, Serial0/1&lt;/P&gt;&lt;P&gt;     10.0.0.0/27 is subnetted, 1 subnets&lt;/P&gt;&lt;P&gt;C       10.100.0.32 is directly connected, Loopback0&lt;/P&gt;&lt;P&gt;R    192.168.2.0/24 [120/1] via 172.16.1.1, 00:00:27, Serial0/1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RouterHQ#&lt;/P&gt;&lt;P&gt;Gateway of last resort is not set&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;     172.16.0.0/30 is subnetted, 1 subnets&lt;/P&gt;&lt;P&gt;C       172.16.1.0 is directly connected, Serial0/1&lt;/P&gt;&lt;P&gt;     10.0.0.0/27 is subnetted, 1 subnets&lt;/P&gt;&lt;P&gt;R       10.100.0.32 [120/1] via 172.16.1.2, 00:00:22, Serial0/1&lt;/P&gt;&lt;P&gt;C    192.168.2.0/24 is directly connected, FastEthernet0/0&lt;/P&gt;&lt;P&gt;RouterHQ#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C3550#&lt;/P&gt;&lt;P&gt;Gateway of last resort is 192.168.3.1 to network 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C    192.168.2.0/24 is directly connected, Vlan7&lt;/P&gt;&lt;P&gt;C    192.168.3.0/24 is directly connected, Vlan2&lt;/P&gt;&lt;P&gt;S*   0.0.0.0/0 [1/0] via 192.168.3.1&lt;/P&gt;&lt;P&gt;C3550#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mypix#&lt;/P&gt;&lt;P&gt;Gateway of last resort is not set&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;S    10.100.0.32 255.255.255.224 [1/0] via 192.168.2.2, DMZ3&lt;/P&gt;&lt;P&gt;C    192.168.2.0 255.255.255.0 is directly connected, DMZ3&lt;/P&gt;&lt;P&gt;C    192.168.3.0 255.255.255.0 is directly connected, Inside&lt;/P&gt;&lt;P&gt;mypix#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3.) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nope.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From my laptop on 192.168.3.20:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C:\&amp;gt;ping 192.168.2.250&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pinging 192.168.2.250 with 32 bytes of data:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Request timed out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C:\&amp;gt;ping 192.168.2.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pinging 192.168.2.1 with 32 bytes of data:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Request timed out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C:\&amp;gt;ping 192.168.3.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pinging 192.168.3.2 with 32 bytes of data:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reply from 192.168.3.2: bytes=32 time&amp;lt;1ms TTL=255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I now realise my routers are not aware of the 192.168.3.x/24 LAN as I have no routes, before I mess about with anything I'll just had back to you as I'm not sure if I can use RIP or just do some static routes.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 09 May 2009 20:54:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-with-pix-lab-using-sub-interfaces/m-p/1166351#M860007</guid>
      <dc:creator>jamesgonzo</dc:creator>
      <dc:date>2009-05-09T20:54:58Z</dc:date>
    </item>
    <item>
      <title>Re: Help with Pix lab using sub interfaces</title>
      <link>https://community.cisco.com/t5/network-security/help-with-pix-lab-using-sub-interfaces/m-p/1166352#M860008</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;James&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If your 3550 is routing which it is why not set the default-gateway on your client to be the L3 vlan interface on the 3550 ie. 192.168.3.2 ? That would automatically allow you to ping 192.168.2.250 on the same switch. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As for pinging the other routers HQ &amp;amp; office then yes you will need to make them aware of 192.168.3.0/24 network. Easiset way to do this would be to configure RIP on the 3550. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The 3550 could still have the default-route set to 192.168.3.1 on the pix for any unknown ie. Internet addresses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a reason why the laptop has it's DG set to the pix rather than the 3550 ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 09 May 2009 21:12:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-with-pix-lab-using-sub-interfaces/m-p/1166352#M860008</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2009-05-09T21:12:24Z</dc:date>
    </item>
    <item>
      <title>Re: Help with Pix lab using sub interfaces</title>
      <link>https://community.cisco.com/t5/network-security/help-with-pix-lab-using-sub-interfaces/m-p/1166353#M860011</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry for the delay I didn't get the email notification for some reason.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following morning I enabled RIPv2 on the pix and advertised the subnets and all worked! Never tried that before. A fresh head helped, but when you asked for the routes it twigged that the routers (WAN) had no idea of the subnets on the Pix, so thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.) Does it matter if I have the Rip on the Pix or 3550?  Just want to make sure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.) I set the DG of the laptop to the Pix as my work do the same, best to use the 3550?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3.) One last request, imagine the remote office on the 10.100.0.32/27 network already has another network on 192.168.3.0/24 somewhere?  Is it possible to NAT my 192.168.3.0/24 LAN to say 192.168.4.0/24?  I don't know how to do Dynamic NAT or static NAT, I guess I would need to advertise the new route aswell?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 May 2009 12:05:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-with-pix-lab-using-sub-interfaces/m-p/1166353#M860011</guid>
      <dc:creator>jamesgonzo</dc:creator>
      <dc:date>2009-05-11T12:05:16Z</dc:date>
    </item>
  </channel>
</rss>

