<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic two subnets on inside interfac of PIX in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/two-subnets-on-inside-interfac-of-pix/m-p/890270#M957550</link>
    <description>&lt;P&gt;I have a PIX with two interfaces, outside and inside.  I would like to add a second IP subnet to the inside interface.  With routers I would use the "secondary" keyword in the "ip address" command. I don't seem to see anything similar with the PIX.  Will I be able to do this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Diego&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 11:44:11 GMT</pubDate>
    <dc:creator>tato386</dc:creator>
    <dc:date>2019-03-11T11:44:11Z</dc:date>
    <item>
      <title>two subnets on inside interfac of PIX</title>
      <link>https://community.cisco.com/t5/network-security/two-subnets-on-inside-interfac-of-pix/m-p/890270#M957550</link>
      <description>&lt;P&gt;I have a PIX with two interfaces, outside and inside.  I would like to add a second IP subnet to the inside interface.  With routers I would use the "secondary" keyword in the "ip address" command. I don't seem to see anything similar with the PIX.  Will I be able to do this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Diego&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:44:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-subnets-on-inside-interfac-of-pix/m-p/890270#M957550</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2019-03-11T11:44:11Z</dc:date>
    </item>
    <item>
      <title>Re: two subnets on inside interfac of PIX</title>
      <link>https://community.cisco.com/t5/network-security/two-subnets-on-inside-interfac-of-pix/m-p/890271#M957551</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ..  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am suspecting you have a PIX 501 model which does not support VLAN interfaces in which case you can't use the internal interface for creating two segments.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps   ..  please rate it if it does !!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Jan 2008 03:46:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-subnets-on-inside-interfac-of-pix/m-p/890271#M957551</guid>
      <dc:creator>Fernando_Meza</dc:creator>
      <dc:date>2008-01-07T03:46:22Z</dc:date>
    </item>
    <item>
      <title>Re: two subnets on inside interfac of PIX</title>
      <link>https://community.cisco.com/t5/network-security/two-subnets-on-inside-interfac-of-pix/m-p/890272#M957552</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am actually working with a 515E and I don't see any VLAN related commands.  However, I hadn't thought about VLANs as a possibility so I will investigate that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Diego&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Jan 2008 06:15:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-subnets-on-inside-interfac-of-pix/m-p/890272#M957552</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2008-01-07T06:15:42Z</dc:date>
    </item>
    <item>
      <title>Re: two subnets on inside interfac of PIX</title>
      <link>https://community.cisco.com/t5/network-security/two-subnets-on-inside-interfac-of-pix/m-p/890273#M957554</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need a minimum of 6.3 version of code to configure VLAN Based Interfaces. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/pix/pix63/release/notes/pixrn63.html#wp45391" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/pix/pix63/release/notes/pixrn63.html#wp45391&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/pix/pix63/configuration/guide/bafwcfg.html#wp1113411" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/pix/pix63/configuration/guide/bafwcfg.html#wp1113411&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Arul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Jan 2008 16:55:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-subnets-on-inside-interfac-of-pix/m-p/890273#M957554</guid>
      <dc:creator>ajagadee</dc:creator>
      <dc:date>2008-01-07T16:55:53Z</dc:date>
    </item>
    <item>
      <title>Re: two subnets on inside interfac of PIX</title>
      <link>https://community.cisco.com/t5/network-security/two-subnets-on-inside-interfac-of-pix/m-p/890274#M957556</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Diego, as said by previous posters, but to be more specific you need minimun version of 6.3(5) to support logical interfaces. For you to be able to split you inside physical into logical segments you will need to use 802.1q trunking to accomplish this. I would like give you a startup  example and requirements if you decide implementing this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;   &lt;/P&gt;&lt;P&gt;Here is a basic script and basic steps.&lt;/P&gt;&lt;P&gt;What is needed : Switch capable of of doing dot1q trunking, for pix side as soon as you assign keyword &lt;PHYSICAL&gt; on the interface 802.1q is automatically turned on without any other commnads as there is none for turning on trunking and your VLAN defined in FW.  &lt;/PHYSICAL&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1- Allocate port on switch to create trunking&lt;/P&gt;&lt;P&gt;between switch and and PIX515E, say you pick Fe0/48 on a 3550 switch.&lt;/P&gt;&lt;P&gt;Define and create VLANs in switch. Say VLAN2 for firewall &lt;NAMEIF inside=""&gt;, VLAN3 for firewall &lt;NAMEIF inside2=""&gt;.&lt;/NAMEIF&gt;&lt;/NAMEIF&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2- Allocate a physical interface in PIX to connect to switch port Fe0/48., on PIX say you allocated inside interface ethernet1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3- Define your security levels, if you are running code 6.3(5) cannot have same security level on interfaces and if you want to not have to deal with NATing between the two you could create a No_NAT acl and apply if to the interfaces, as for security you could use 100 for inside and 99 for inside2 interfaces. If you are running code version 7.x or above you have the option to use same secutity level on interfaces and use &lt;SAME-SECURITY trafic="" permit="" inter-interface=""&gt; command to avoid acls.    &lt;/SAME-SECURITY&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;example using 10.2.2.0/24 as VLAN2  and 10.3.3.0/24 as VLAN3 for trusted LAN.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;If using 6.3(5)&lt;/B&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface ethernet1 100&lt;/P&gt;&lt;P&gt;interface ethernet1 vlan2 physical&lt;/P&gt;&lt;P&gt;interface ethernet1 vlan3 logical&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;nameif vlan3 inside2 security99&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip address inside 10.2.2.1 255.255.255.0&lt;/P&gt;&lt;P&gt;ip address inside2 10.3.3.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global(outside) 1 interface&lt;/P&gt;&lt;P&gt;nat(vlan2) 1 10.2.2.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;nat(vlan3) 1 10.3.3.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Switch_3550: &lt;/P&gt;&lt;P&gt;vlan database &lt;/P&gt;&lt;P&gt;vtp transparent &lt;/P&gt;&lt;P&gt;vtp domain test &lt;/P&gt;&lt;P&gt;vtp password cisco &lt;/P&gt;&lt;P&gt;vlan 2 name FW_Inside_10.2.2.0/24 &lt;/P&gt;&lt;P&gt;vlan 3 name FW_inside2_10.3.3.0/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interface fastethernet0/48 &lt;/P&gt;&lt;P&gt;Description trunk_Connection_PIX_Ethernet1 &lt;/P&gt;&lt;P&gt;speed 100 &lt;/P&gt;&lt;P&gt;duplex full &lt;/P&gt;&lt;P&gt;switchport mode trunk &lt;/P&gt;&lt;P&gt;switchport trunk encapsulation dot1q &lt;/P&gt;&lt;P&gt;switchport trunk allowed vlan 2,3 &lt;/P&gt;&lt;P&gt;no shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;If using PIX 7.x code and above&lt;/B&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface ethernet1 &lt;/P&gt;&lt;P&gt;speed 100 &lt;/P&gt;&lt;P&gt;duplex full &lt;/P&gt;&lt;P&gt;nameif Inside_LAN &lt;/P&gt;&lt;P&gt;security-level 100 &lt;/P&gt;&lt;P&gt;no ip address &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet1/1.1 &lt;/P&gt;&lt;P&gt;vlan 2 &lt;/P&gt;&lt;P&gt;nameif vlan2 &lt;/P&gt;&lt;P&gt;security-level 100 &lt;/P&gt;&lt;P&gt;ip address 10.2.2.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet1/1.2 &lt;/P&gt;&lt;P&gt;vlan 3 &lt;/P&gt;&lt;P&gt;nameif vlan3 &lt;/P&gt;&lt;P&gt;security-level 100 &lt;/P&gt;&lt;P&gt;ip address 10.3.3.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global(outside) 1 interface&lt;/P&gt;&lt;P&gt;nat(vlan2) 1 10.2.2.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;nat(vlan3) 1 10.3.3.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for switch part same principle as 6.3(5) example.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Jorge&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Jan 2008 18:37:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-subnets-on-inside-interfac-of-pix/m-p/890274#M957556</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-01-07T18:37:04Z</dc:date>
    </item>
    <item>
      <title>Re: two subnets on inside interfac of PIX</title>
      <link>https://community.cisco.com/t5/network-security/two-subnets-on-inside-interfac-of-pix/m-p/890275#M957557</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great info!  Thank you very much guys.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Diego&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jan 2008 13:57:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-subnets-on-inside-interfac-of-pix/m-p/890275#M957557</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2008-01-08T13:57:13Z</dc:date>
    </item>
  </channel>
</rss>

