06-20-2005 01:12 AM - edited 02-21-2020 12:13 AM
Hi,
I was recently told that it is not possible to route traffic coming in via e.g. Eth1 out of Eth1 again to another router for example.
I'm not convinced though, and was wondering if any of you know of a way to do it? It is some special command, a question of rules or simply the need for a firmware update?
Thanks in advance,
Rasmus
06-20-2005 02:25 AM
Hello Rasmus
You are right... icmp redirects arent possible with PIX.. this is feature specific and does not depend on any commands or hardware...
try putting a router before/after pix and do redirection on router instead of pix...
just have a look at this pix faq document..
HTH
Raj
06-27-2005 06:43 AM
I had the same need a little over a year ago and I opened a TAC case to ask if there were any "undocumented commands" to get the PIX to route packets in/out, for my particular SOHO need. I was advised it was NOT possible. I had to put a router just before the PIX, as has been mentioned in this thread.
06-27-2005 07:16 AM
Routing packets in/out of the same interface is known as hair-pinning. This is not supported in 6.x or previous versions, but you can enable it on PIX 7.x
HTH
06-27-2005 11:00 PM
Really? That sounds great. Actually I think it weird they didn't implement it in earlier versions - a lot of other firewalls can do it.
Is it easy to configure, or is it rocket science?
06-28-2005 01:18 AM
You can enable hair-pinning ONLY for VPN....
07-01-2005 03:26 PM
Intra-interface firewalling is possible on both FWSM 2.3 amd PIX 7.0 using the 'same-security-traffic permit intra-interface' command.
On the FWSM this can be for any traffic. However on the PIX I beleive this is allowed only for IPSec traffic - VPN Hub-Spoke scenario to allow for spoke-spoke communication after firewalling on same interface.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide