cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
845
Views
0
Helpful
7
Replies

PIX Routing problems

RobboRobson
Level 1
Level 1

Dear all

I currently have at my HQ a PIX 515 which everyone connects to the internet through.

I have just installed a VPN Concentrator at the HQ and installed a VPN to a PIX 501 at a remote site.

I want the clients to be able to connect to that site so i put a static route on the 515 to point through the vpn concentrator.

Unfortunately the PIX doesn't seem to be routing the traffic to the remote site.

Any ideas??

I can do a route add on the local clients and ping the remote site so i know that the VPN is working correctly but the pix just doesn't seem to route any traffic.

All i have done is put in

route inside 192.168.30.0 255.255.255.0 192.168.1.6 1

Should i need to do anything else??

Thanks

James

7 Replies 7

a.alekseev
Level 7
Level 7

A pix is not a router.

Before PIXOS7.0 pix could not route traffic between vpn.

PIX can not send a packet comming on the interface back to the same interface.

Do you know a link to where i could get the latest update for the PIX or if you could email me the files?

I tryed to find it on the Cisco website but they said there weren't any updates.

This would be much appreciated

Thanks

James

wla1evc
Level 1
Level 1

the inside interface of your pix, i'm assuming is connected to a router. you'll need to put have a route for your vpn subnets pointing to the inside int of your concentrator.

Sorry i wasn't clear enough

The PIX internal interface IP is 192.168.1.3

The Concentrator internal interface IP is 192.168.1.6

The Remote Sites IP Range is 192.168.30.0

On the PIX i have put in

route inside 192.168.30.0 255.255.255.0 192.168.1.6 1

But the PIX still won't route traffic to the remote site

you have a static route pointing to the concentrator, but does your concentrator have the route to get back to the subnets

This maybe a dumb question, but is the PIX the default gateway on your network?

If so the pix does not have the ability to redirect clients using its routing tables.

As stated preveously the PIX is no a router, you may need to add static routes on your internal machines.

Review Cisco Networking for a $25 gift card