cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
503
Views
0
Helpful
2
Replies

PIX 7.0(4) Hairpinning or routing through the same interface

slaurin
Level 1
Level 1

Hi all,

I have read that PIX version 7 and up allows "hairpinning" encrypted traffic. That's beautiful, but did someone find out how to route regular IP traffic through the same interface (same security level) on a PIX running version 7up? Alernatively, can we do it through a loopback interface like with IOS ?

Thanks

Simon Laurin

2 Replies 2

j.docio
Level 1
Level 1

Hi,

it isn't possible with PIXs.

At this moment FWSM supports this feature (routing through the same interface), I think that Cisco will add this feature on PIXs in a near future ...

hope this helps.

Juan.

v-naughton
Level 1
Level 1

I have set this up for hub and spoke vpn clients and it works like a charm. I used the same-security-traffic perpit intra-interface. The key here is intra-interface which specifies ipsec traffic, if you use inter-interface it allows communication between interfaces with the same security level but you would need a seperate physical interface.....have a look at the command guide here

http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_70/cmd_ref/index.htm

Review Cisco Networking for a $25 gift card