01-19-2007 08:28 AM - edited 03-11-2019 02:22 AM
How would I go about allowing a VLAN full access to the internet through a PIX.
Outside Interface: 88.88.88.88
Inside Interface: 10.36.1.1
Vlan35: 10.35.1.2
Version 6.3(3)
I have very limited PIX knowledge, so any help would be appreciated.
Solved! Go to Solution.
01-19-2007 01:12 PM
So you then have a static route in the 3550 point to the Server_vlan interface on the PIX?
01-19-2007 08:44 AM
Too many assumptions. Please sanitize and post your config.
01-19-2007 09:04 AM
Sorry about that. Current Pix config is attached.
VLAN Routing is being handled by the 3550 switch at 10.36.3.1 / 10.44.1.1 / 10.35.1.1 with
!
ip default-gateway 10.36.1.1
ip classless
ip route 0.0.0.0 0.0.0.0 10.36.1.1
!
Currently clients on VLAN 1 can access the outside, but VLANs 35 and 44 cannot.
From what I can see, if I send a ping from a device on VLAN35 the switch routes it to the Pix inside interface, but when the ping is returned it cannot reach that device from the inside interface.
The pix can ping the device through the VLAN interface, but not through the inside interface. It just seems like I'm missing something really simple here...
01-19-2007 09:31 AM
deleted
01-19-2007 09:42 AM
Everything looks good except that the following line:
access-group ServerVLAN_access_in in interface ServerVLAN
The command is OK, but you do not have an ACL named ServerVLAN_access_in. Because there is no ACL, a 'deny ip any any' is implied blocking all traffic. You could either remove the access-group command or create the ACL allowing whatever you need access to on the outside.
HTH and please rate.
01-19-2007 10:09 AM
01-19-2007 10:20 AM
Check your logs, they should help point us in the right direction. I'll check the statics.
01-19-2007 10:23 AM
Statics look OK. What's the default gateway of your servers? From the PIX can you successfully ping the mail server?
01-19-2007 10:36 AM
The server default gateway is the VLAN IP of the layer 3 switch, so 10.35.1.1.
From the Pix I can ping with
ping mail
ping ServerVLAN mail
but cannot ping with
ping inside mail
01-19-2007 10:46 AM
The GuestWLAN VLAN (44) works just fine after I added nat (GuestWLAN) 1 10.44.1.0 255.255.255.0 0 0.
01-19-2007 01:12 PM
So you then have a static route in the 3550 point to the Server_vlan interface on the PIX?
01-19-2007 08:16 PM
Oh wow -- talk about focusing on the wrong place. Here I was convinced that it was a PIX configuration issue and never reviewed the switch. Doh!
I had A route configured on the 3550 -
ip route 0.0.0.0 0.0.0.0 10.36.1.1
But never added the route for VLAN35 -
ip route 0.0.0.0 0.0.0.0 10.35.1.2
Thanks for pointing this out for me! What a relief to have this resolved!
01-19-2007 10:50 PM
Guess that didn't work after all. Sometimes it works, sometimes it doesn't - I guess it depends upon which route it chooses.
Is there another way to define the route for each VLAN?
01-22-2007 06:57 AM
Is there a reason you're using the 3550 as the DG? It's a security vulnerability. Try setting the PIX as your DG.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide