cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
216
Views
0
Helpful
1
Replies

Possible to use PIX as VLAN router?

Brian M
Level 1
Level 1

Is it possible to use a PIX 515 as a Inter VLAN Router? I have a 515 running PIX OS7 that is configured for 2 VLANS. The devices on each vlan can see the PIX just fine but I cannot route between the VLANS. I do have the "same-security-traffic permit intra-interface" command setup but still no luck.

Thanks!!

1 Reply 1

gpulos
Level 8
Level 8

it may be possible to use pix as a interVLAN router but it is highly discouraged. (cisco or good netEng would say NO!)

among other 'cons' of using a pix for this are:

* administration - high maintenance to setup pix for all vlans access to/from each other

* packet inspection induces latency

* must specifically permit deny all required ports (TCP/UDP) let alone other protocols

* must use dmz interfaces for more than 2 vlans

there are many more reasons this is not a solution for your needs.

consider using an inexpensive L3 switch such as 3550 with basic routing or even a 2800 series router. (or even a 2600 router gotten cheap from ebay or the likes)