cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
525
Views
0
Helpful
5
Replies

Cisco PIX VLAN

cbayadmin_mum
Level 1
Level 1

HI,

I have Cisco PIX 515E ,have created VLAN on inside interface as VLAN2 (logical interface),assigned it an ip 172.17.1.xx ....Now i also have a 3-com super stack 3 switch on which i have created a VLAN2...i have connected a machine on the port of VLAN2 with ip 172.17.1.xxx (of the same subnet as of VLAN2 PIX) and on the same switch connected the PIX in the VLAN2

This means my machine is in VLAN2, the PIX inside interface is on VLAN2 and the PIX have a logicla interface with VLAn2 of the same subnet as my machine ...

Problem: i am not able to Ping to PIX interface with VLAN2 IP

5 Replies 5

sachinraja
Level 9
Level 9

Hello

The PIX inside and the logical interface cannot be on the same VLAN. You need to have different networks assigned to the PIX inside and the logical interface.. On the switch you need to configure trunking on the port which is connected to PIX and not in VLAN 2...

Refer to this document and see if you done the right configs.. post ur configs if possible..

http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_configuration_guide_chapter09186a0080172786.html#wp1113411

hope this helps.. Raj

Yess the logical interface is assigned VLAN2 ,the physical inside interface has no VLAN ....And yes the physical interface is assigned the Network ip 172.17.0.XX

Any idea about trunking in 3-com switches ??will help a lot

hello,

Not really sure of the trunking config in 3-com. havent worked with that much. i have seen people configuring these switches through GUI, where you tag/untag a port and include it as a trunk. you can search this on the 3com knowledgebase.

Raj

Raj,

We had the port where PIX was connected tagged but still i was not able to PING from the machine in VLAN2 to the PIX VLAN2 interface IP

On the workstation, after a ping attempt, run a command to display the arp table. See if you have a valid mac address that corresponds to the pix interface for that intf ip address. If you do not have an arp table entry, then the issue may be with the switch port config that the pix intf plugs into. If there is more than one switch involved, then the issue may lie with the trunk connection betweent them. Maybe vlan 2 is being pruned from the trunk link?

Review Cisco Networking for a $25 gift card