<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX VLANs in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-vlans/m-p/911499#M962690</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,  where is the trunk config on the  PIX can you post that portion.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Jorge&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 22 Sep 2007 21:33:04 GMT</pubDate>
    <dc:creator>JORGE RODRIGUEZ</dc:creator>
    <dc:date>2007-09-22T21:33:04Z</dc:date>
    <item>
      <title>PIX VLANs</title>
      <link>https://community.cisco.com/t5/network-security/pix-vlans/m-p/911498#M962689</link>
      <description>&lt;P&gt;I have a PIX 515 running 7.2(2).   I am trying to set up a public and a private network to separate the traffic.  My PIX doesn't seem to want to participate in the VLAN.  VLAN 1 is my private VLAN and VLAN 2 is my public VLAN.  My Switch is a 3560.&lt;/P&gt;&lt;P&gt;PIX Config&lt;/P&gt;&lt;P&gt;interface Ethernet1&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet1.1&lt;/P&gt;&lt;P&gt; vlan 1&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.0.0.1 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet1.2&lt;/P&gt;&lt;P&gt; vlan 2&lt;/P&gt;&lt;P&gt; nameif public&lt;/P&gt;&lt;P&gt; security-level 10&lt;/P&gt;&lt;P&gt; ip address 172.16.0.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Switch Config&lt;/P&gt;&lt;P&gt;interface FastEthernet0/1&lt;/P&gt;&lt;P&gt; switchport trunk encapsulation dot1q&lt;/P&gt;&lt;P&gt; switchport mode trunk&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; ip address 10.0.0.221 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't ping either direction.  I do see the MAC address for the PIX in the ARP cache on the switch.&lt;/P&gt;&lt;P&gt;What am I doing wrong?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:15:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-vlans/m-p/911498#M962689</guid>
      <dc:creator>mdieken01</dc:creator>
      <dc:date>2019-03-11T11:15:31Z</dc:date>
    </item>
    <item>
      <title>Re: PIX VLANs</title>
      <link>https://community.cisco.com/t5/network-security/pix-vlans/m-p/911499#M962690</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,  where is the trunk config on the  PIX can you post that portion.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Jorge&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 22 Sep 2007 21:33:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-vlans/m-p/911499#M962690</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2007-09-22T21:33:04Z</dc:date>
    </item>
    <item>
      <title>Re: PIX VLANs</title>
      <link>https://community.cisco.com/t5/network-security/pix-vlans/m-p/911500#M962691</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What Trunk configuration for the PIX?  Maybe that is what I am missing.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 22 Sep 2007 21:36:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-vlans/m-p/911500#M962691</guid>
      <dc:creator>mdieken01</dc:creator>
      <dc:date>2007-09-22T21:36:15Z</dc:date>
    </item>
    <item>
      <title>Re: PIX VLANs</title>
      <link>https://community.cisco.com/t5/network-security/pix-vlans/m-p/911501#M962692</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,  where is the trunk config on the  PIX can you post that portion.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[EDIT]  never mind and sorry about that,   802.1q  is automatically enable when creating logical interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is the interface  up on the PIX where you have the trunk.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you connect a host in one of the vlans  and try to ping its defaul gateway say  10.0.0.1 can you get replies.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Jorge&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 22 Sep 2007 21:45:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-vlans/m-p/911501#M962692</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2007-09-22T21:45:05Z</dc:date>
    </item>
    <item>
      <title>Re: PIX VLANs</title>
      <link>https://community.cisco.com/t5/network-security/pix-vlans/m-p/911502#M962693</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mark, few things to look into.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First:  From the PIX if you can ping the interfaces 172.16.0.1 and 10.0.0.1 that will&lt;/P&gt;&lt;P&gt;indicate they are pingable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Second: From the switch issues " show interface trunk "  to see the vlans passing through that trunk.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Third:  Make sure you have created the vlans in the switch correspnding to these two new routable networks , check your vlan database.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Forth: Assign proper vlan membership on ports corresponding to these two new vlans.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fith:  From lower security level to highest security level you need access list to allow communications from  172.16.0.0/24 to 10.0.0.0/24 network, that include icmp or any other ports required.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Jorge&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 23 Sep 2007 15:40:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-vlans/m-p/911502#M962693</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2007-09-23T15:40:22Z</dc:date>
    </item>
  </channel>
</rss>

