<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX v6.3 issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-v6-3-issue/m-p/1055615#M895201</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for your help,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but why should not have a DG of the PIX if you have a layer 3 routing device in your network?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I already test your suggest it's working fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;yhanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 14 Oct 2008 09:17:21 GMT</pubDate>
    <dc:creator>youssef_1985</dc:creator>
    <dc:date>2008-10-14T09:17:21Z</dc:date>
    <item>
      <title>PIX v6.3 issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-v6-3-issue/m-p/1055611#M895192</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;my router connect in inside I have other subnet to reach Behind  my Router (add 172.20.1.250) and i can ping to any subnet in outside&lt;/P&gt;&lt;P&gt;but not Behind my router but if i ping from my PIX it's Successful toward all subnet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am connected in inside and my GW is 172.20.1.10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this is my config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:56:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-v6-3-issue/m-p/1055611#M895192</guid>
      <dc:creator>youssef_1985</dc:creator>
      <dc:date>2019-03-11T13:56:23Z</dc:date>
    </item>
    <item>
      <title>Re: PIX v6.3 issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-v6-3-issue/m-p/1055612#M895195</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you trying to ping from the "outside" to the "inside" ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if so - you do not have any static nat translations for 172.20.1.250.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Oct 2008 06:55:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-v6-3-issue/m-p/1055612#M895195</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2008-10-13T06:55:08Z</dc:date>
    </item>
    <item>
      <title>Re: PIX v6.3 issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-v6-3-issue/m-p/1055613#M895197</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i don't need ping from outside to inside&lt;/P&gt;&lt;P&gt;my objectify is:&lt;/P&gt;&lt;P&gt;from my PC (172.20.1.25 gw PIX) ping subnets behind my router(172.20.1.250)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;test from my PC:&lt;/P&gt;&lt;P&gt;ping subnets outside---&amp;gt;OK&lt;/P&gt;&lt;P&gt;ping gw PIX -------&amp;gt;OK&lt;/P&gt;&lt;P&gt;ping gw Router----&amp;gt;OK&lt;/P&gt;&lt;P&gt;ping subnet behind Router-----&amp;gt;NOK "problem"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Oct 2008 08:37:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-v6-3-issue/m-p/1055613#M895197</guid>
      <dc:creator>youssef_1985</dc:creator>
      <dc:date>2008-10-14T08:37:36Z</dc:date>
    </item>
    <item>
      <title>Re: PIX v6.3 issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-v6-3-issue/m-p/1055614#M895199</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Firstly you design is wrong, it is possible to do what you want using the PIX, but you will have to upgrade and do some complicated config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) You should not have a DG of the PIX if you have a layer 3 routing device in your network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I suggest you do the following:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Change the DG of your PC to 172.20.1.250.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the router add a static route:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip route 192.168.1.0 255.255.255.0 172.20.1.10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will fix your issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Oct 2008 08:52:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-v6-3-issue/m-p/1055614#M895199</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2008-10-14T08:52:50Z</dc:date>
    </item>
    <item>
      <title>Re: PIX v6.3 issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-v6-3-issue/m-p/1055615#M895201</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for your help,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but why should not have a DG of the PIX if you have a layer 3 routing device in your network?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I already test your suggest it's working fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;yhanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Oct 2008 09:17:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-v6-3-issue/m-p/1055615#M895201</guid>
      <dc:creator>youssef_1985</dc:creator>
      <dc:date>2008-10-14T09:17:21Z</dc:date>
    </item>
    <item>
      <title>Re: PIX v6.3 issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-v6-3-issue/m-p/1055616#M895203</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Honestly - it's a bad use of networking devices.  The PIX is a "Firewall" to protect and give access between a trusted an un-trusted networks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A router is a layer 3 IP routing device, design for routing IP subnet works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have both devices available - then the router should be a router, the firewall should be a firewall.  Only in cases where you only have one should you really make the devices duel purpose,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;besides, your PIX was running 6.3 code - you would need to upgrade to 7.x or 8.x to do what you wanted to do, which would have been:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,inside) 172.20.1.0 172.20.1.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the above would:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Not nat any traffic from 172.20.1.0 to 172.20.1.0&lt;/P&gt;&lt;P&gt;2) Allow traffic recevied on the inside interface to be transmitted back out of the inside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you can see - the above is exactly 100% what a router does..... do you understand?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Oct 2008 09:32:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-v6-3-issue/m-p/1055616#M895203</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2008-10-14T09:32:52Z</dc:date>
    </item>
    <item>
      <title>Re: PIX v6.3 issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-v6-3-issue/m-p/1055617#M895204</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes thank you very much.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Oct 2008 09:42:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-v6-3-issue/m-p/1055617#M895204</guid>
      <dc:creator>youssef_1985</dc:creator>
      <dc:date>2008-10-14T09:42:54Z</dc:date>
    </item>
    <item>
      <title>Re: PIX v6.3 issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-v6-3-issue/m-p/1055618#M895205</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;np - glad to help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Oct 2008 09:44:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-v6-3-issue/m-p/1055618#M895205</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2008-10-14T09:44:23Z</dc:date>
    </item>
    <item>
      <title>Re: PIX v6.3 issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-v6-3-issue/m-p/1055619#M895206</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*Allow traffic recevied on the inside interface to be transmitted back out of the inside interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;why CMD i need to use for this?"access-list"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Oct 2008 10:44:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-v6-3-issue/m-p/1055619#M895206</guid>
      <dc:creator>youssef_1985</dc:creator>
      <dc:date>2008-10-14T10:44:51Z</dc:date>
    </item>
    <item>
      <title>Re: PIX v6.3 issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-v6-3-issue/m-p/1055620#M895207</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;same-security-traffic permit intra-interface - is the command you need.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BUT as I have previsouly posted - you NEED to upgrade to either 7.x or 8.x of IOS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Oct 2008 11:11:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-v6-3-issue/m-p/1055620#M895207</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2008-10-14T11:11:54Z</dc:date>
    </item>
  </channel>
</rss>

