<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Pix 515E Multiple outside and multiple inside interfaces  in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-515e-multiple-outside-and-multiple-inside-interfaces/m-p/900470#M974703</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One of the first obvious things is that you are not routing any traffic via the cable interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need an additional 0.0.0.0 0.0.0.0 via your cable DFGW.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside-cable 0.0.0.0 0.0.0.0 x.x.x.x&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 21 Sep 2007 11:26:17 GMT</pubDate>
    <dc:creator>jon.humphries</dc:creator>
    <dc:date>2007-09-21T11:26:17Z</dc:date>
    <item>
      <title>Pix 515E Multiple outside and multiple inside interfaces</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-multiple-outside-and-multiple-inside-interfaces/m-p/900467#M974700</link>
      <description>&lt;P&gt;I'm having a tough time trying to configure our PIX 515E to pull double-duty firewalling our two networks.  Basically we have two inside (private) subnets (192.168.1.0 &amp;amp; 192.168.100.0) and two internet connections.  One is a T1 and the other is a cable.  Our normal users get dumped onto a Vlan that has access to the T1, while visitors get put on a Vlan that access cable.  So far I've been successful in getting T1 Vlan traffic through the PIX and out to the internet, but it blocks traffic to the cable modem.  I've setup two global nat pools and two inside nat statements.  Is there anything obvious I'm missing?  Is the PIX even capable of firewalling two separate outside networks?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:14:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-multiple-outside-and-multiple-inside-interfaces/m-p/900467#M974700</guid>
      <dc:creator>ssewallatrc</dc:creator>
      <dc:date>2019-03-11T11:14:30Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 515E Multiple outside and multiple inside interfaces</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-multiple-outside-and-multiple-inside-interfaces/m-p/900468#M974701</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is totally possible to firewall "two outside connections"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are also many ways that you can achieve this depending also on the type of license you have. It is possible to run the firewall in contexts, but I don't think you need to get this complicated for a simple division of network traffic. If you require further assistance, I will need to see the configs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon Humphries&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Sep 2007 22:28:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-multiple-outside-and-multiple-inside-interfaces/m-p/900468#M974701</guid>
      <dc:creator>jon.humphries</dc:creator>
      <dc:date>2007-09-20T22:28:35Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 515E Multiple outside and multiple inside interfaces</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-multiple-outside-and-multiple-inside-interfaces/m-p/900469#M974702</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jon,&lt;/P&gt;&lt;P&gt;   Here's what I have so far.  I haven't setup any rules other than the defaults yet.  Want to get the cable problem solved first. &lt;/P&gt;&lt;P&gt;---------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hostname pixfirewall&lt;/P&gt;&lt;P&gt;domain-name inside.net&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;dns-guard&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0&lt;/P&gt;&lt;P&gt; nameif outside-t1&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 192.168.75.100 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet1&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.0.200 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet1.50&lt;/P&gt;&lt;P&gt; vlan 50&lt;/P&gt;&lt;P&gt; nameif inside-biznet&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.1.50.1 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt; interface Ethernet1.666&lt;/P&gt;&lt;P&gt; vlan 666&lt;/P&gt;&lt;P&gt; nameif inside-cable&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.1.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet2&lt;/P&gt;&lt;P&gt; mac-address 0006.25d7.ed64&lt;/P&gt;&lt;P&gt; nameif outside-cable&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address dhcp setroute &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt; domain-name inside.net&lt;/P&gt;&lt;P&gt;access-list acl_grp1 extended permit ip any any &lt;/P&gt;&lt;P&gt;mtu outside-t1 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu inside-biznet 1500&lt;/P&gt;&lt;P&gt;mtu inside-cable 1500&lt;/P&gt;&lt;P&gt;mtu outside-cable 1500&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;nat-control&lt;/P&gt;&lt;P&gt;global (outside-t1) 1 interface&lt;/P&gt;&lt;P&gt;global (outside-cable) 2 interface&lt;/P&gt;&lt;P&gt;nat (inside-biznet) 1 10.1.50.0 255.255.255.0&lt;/P&gt;&lt;P&gt;nat (inside-cable) 2 192.168.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;route outside-t1 0.0.0.0 0.0.0.0 192.168.75.1 1&lt;/P&gt;&lt;P&gt;dhcpd address 192.168.1.100-192.168.1.200 inside-cable&lt;/P&gt;&lt;P&gt;dhcpd auto_config outside-cable interface inside-cable&lt;/P&gt;&lt;P&gt;dhcpd enable inside-cable&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns migrated_dns_map_1&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;  message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;  inspect dns migrated_dns_map_1 &lt;/P&gt;&lt;P&gt;  inspect ftp &lt;/P&gt;&lt;P&gt;  inspect h323 h225 &lt;/P&gt;&lt;P&gt;  inspect h323 ras &lt;/P&gt;&lt;P&gt;  inspect rsh &lt;/P&gt;&lt;P&gt;  inspect rtsp &lt;/P&gt;&lt;P&gt;  inspect esmtp &lt;/P&gt;&lt;P&gt;  inspect sqlnet &lt;/P&gt;&lt;P&gt;  inspect skinny &lt;/P&gt;&lt;P&gt;  inspect sunrpc &lt;/P&gt;&lt;P&gt;  inspect xdmcp &lt;/P&gt;&lt;P&gt;  inspect sip &lt;/P&gt;&lt;P&gt;  inspect netbios &lt;/P&gt;&lt;P&gt;  inspect tftp &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;prompt hostname context &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Sep 2007 11:14:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-multiple-outside-and-multiple-inside-interfaces/m-p/900469#M974702</guid>
      <dc:creator>ssewallatrc</dc:creator>
      <dc:date>2007-09-21T11:14:39Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 515E Multiple outside and multiple inside interfaces</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-multiple-outside-and-multiple-inside-interfaces/m-p/900470#M974703</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One of the first obvious things is that you are not routing any traffic via the cable interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need an additional 0.0.0.0 0.0.0.0 via your cable DFGW.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside-cable 0.0.0.0 0.0.0.0 x.x.x.x&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Sep 2007 11:26:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-multiple-outside-and-multiple-inside-interfaces/m-p/900470#M974703</guid>
      <dc:creator>jon.humphries</dc:creator>
      <dc:date>2007-09-21T11:26:17Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 515E Multiple outside and multiple inside interfaces</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-multiple-outside-and-multiple-inside-interfaces/m-p/900471#M974704</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I thought the dhcp setroute command on the outside-cable interface would handle that?  The problem is, how am I supposed to determine my cable ISP's default gateway if it could change (they use dynamic ips)?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Sep 2007 16:04:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-multiple-outside-and-multiple-inside-interfaces/m-p/900471#M974704</guid>
      <dc:creator>ssewallatrc</dc:creator>
      <dc:date>2007-09-21T16:04:28Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 515E Multiple outside and multiple inside interfaces</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-multiple-outside-and-multiple-inside-interfaces/m-p/900472#M974705</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;According to your configuration, you are running version 7.x, so you should be able to use the security context, however on the PIX515E this is a licensed feature (and rather $$$)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The main problem is routing with two different default routes. &lt;/P&gt;&lt;P&gt;Since the ASA/PIX doesn't support policy based routing, I don't see that you have any options other than:&lt;/P&gt;&lt;P&gt;1) Get PIX-SW-SC-5 (5 security contexts) as well as an upgrade to Unrestricted if your are running a restricted license. Security contexts are not supported on Restricted (R) models.&lt;/P&gt;&lt;P&gt;2) Buy a cheap Cable router and hook this up to your guest VLAN and keep this traffic outside of your PIX.&lt;/P&gt;&lt;P&gt;3) Put a Cisco router on the outside that has PBR and that can connect to both the Cable and the T1. &lt;/P&gt;&lt;P&gt;4) Replace your PIX with an ASA5510 that has the Security Plus license (incl. 2 Security Contexts)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In solution 1, 3 and 4 above you could set up the cable connection as a backup connection for your T1 users. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry, but I am afraid that you will not be able to achieve what you are trying with your current solution. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could although use QoS to prioritize your LAN users. Then your cable connection could work as a backup interface for your T1, but not both at the same time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Harald.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 22 Sep 2007 18:30:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-multiple-outside-and-multiple-inside-interfaces/m-p/900472#M974705</guid>
      <dc:creator>Harald-Norvik</dc:creator>
      <dc:date>2007-09-22T18:30:49Z</dc:date>
    </item>
  </channel>
</rss>

