cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
856
Views
0
Helpful
4
Replies

routing problems

rmeder
Community Member

I have a 2 PIX 501s. PIX-1 has it's inside interface on the network 192.168.x.0 and PIX-2 has it's inside interface on the network 10.0.x.0 and outside interface on 192.168.x.2 which are both internal lans. I need to setup a route from 192.168 to the 10.0 I added a route to the config which I figured would accomplish this, but when I try to telnet from the 192.168 to the 10.0 I receive a syslog error stating that a route to 10.0.x.100 does not exist from 192.168.x.10. This error is from PIX-1 The following is the config of PIX-1

Result of firewall command: "sh run"

: Saved

:

PIX Version 6.3(4)

interface ethernet0 auto

interface ethernet1 100full

nameif ethernet0 outside security0

nameif ethernet1 inside security100

enable password XXXX encrypted

passwd XXXX encrypted

hostname PIX-1

domain-name nexstore.internal

fixup protocol dns maximum-length 512

fixup protocol ftp 21

fixup protocol h323 h225 1720

fixup protocol h323 ras 1718-1719

fixup protocol http 80

fixup protocol rsh 514

fixup protocol rtsp 554

fixup protocol sip 5060

fixup protocol sip udp 5060

fixup protocol skinny 2000

fixup protocol smtp 25

fixup protocol sqlnet 1521

fixup protocol tftp 69

names

name 192.168.x.0 Remote_PIX_Corporate

access-list 101 permit tcp any host 216.xx.xx.70 eq https

access-list 101 permit tcp any host 216.xx.xx.70 eq 3389

access-list 101 permit icmp any any unreachable

access-list 101 permit icmp any any time-exceeded

access-list 101 permit icmp any any echo-reply

access-list 101 permit tcp any host 216.xx.xx.71 eq pcanywhere-data

access-list 101 permit tcp any host 216.xx.xx.71 eq 5632

access-list 101 permit tcp any host 216.xx.xx.71 eq https

access-list inside_outbound_nat0_acl permit ip any 10.x.0.96 255.255.255.224

access-list outside_cryptomap_dyn_20 permit ip any 10.x.0.96 255.255.255.224

access-list nexstore_splitTunnelAcl permit ip Remote_PIX_Corporate 255.255.255.0 any

pager lines 24

logging on

logging trap debugging

logging host inside 192.168.x.10

mtu outside 1500

mtu inside 1500

ip address outside 216.xx.xx.66 255.255.255.240

ip address inside 192.168.x.1 255.255.255.0

ip audit info action alarm

ip audit attack action alarm

ip local pool remote_IP 10.x.0.100-10.x.0.119

pdm location 192.168.x.10 255.255.255.255 inside

pdm location 192.168.x.12 255.255.255.255 inside

pdm location 192.168.x.11 255.255.255.255 inside

pdm location Remote_PIX_Corporate 255.255.255.0 outside

pdm location 10.0.x.100 255.255.255.255 inside

pdm location 10.0.x.0 255.255.255.0 inside

pdm logging informational 100

pdm history enable

arp timeout 14400

global (outside) 1 interface

nat (inside) 0 access-list inside_outbound_nat0_acl

nat (inside) 1 0.0.0.0 0.0.0.0 0 0

static (inside,outside) tcp 216.xx.xx.70 https 192.168.x.12 https netmask 255.255.255.255 0 0

static (inside,outside) tcp 216.xx.xx.70 3389 192.168.x.12 3389 netmask 255.255.255.255 0 0

static (inside,outside) tcp 216.xx.xx.71 pcanywhere-data 192.168.x.11 pcanywhere-data netmask 255.255.255.255 0 0

static (inside,outside) tcp 216.xx.xx.71 5632 192.168.x.11 5632 netmask 255.255.255.255 0 0

static (inside,outside) tcp 216.xx.xx.70 3390 192.168.x.11 3389 netmask 255.255.255.255 0 0

static (inside,outside) tcp 216.64.81.71 https 192.168.x.11 https netmask 255.255.255.255 0 0

access-group 101 in interface outside

route outside 0.0.0.0 0.0.0.0 216.xx.xx.65 1

route inside 10.0.x.0 255.255.255.0 192.168.x.2 1

route inside 10.0.x.100 255.255.255.255 192.168.x.2 1

route inside 192.x.x.0 255.255.255.0 192.168.x.3 1

timeout xlate 0:05:00

timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00

timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00

timeout uauth 0:05:00 absolute

console timeout 0

terminal width 80

Cryptochecksum:xxxxx

: end

1 Accepted Solution

Accepted Solutions

In theory what you say is correct but in actuality it wont happen. Reason is that the Pix will not send it back out the same interface.

Traffic from 192.168.x.10 goes to Pix1 which has the route to 10.0.x.0 via 192.168.x.2 (Pix2 Outside) when the pix gets this it drops the packet because it violates the security design of the Pix.

Any "router" would do .. if you are looking cheap, Linux box, Linksys, *shudder* Windows.

View solution in original post

4 Replies 4

erickflamenco
Level 3
Level 3

I guess the default gw for 192.168.x.10 is 192.168.x.1 and taking in account that the PIX is not a router, you should add a persistent static route to host .10 to look for network 10.0 through PIX-2's outside interface.If this is a windows based host, this should be something like

route - p add 10.0.x.0 mask 255.255.255.0 192.168.x.2

PIX-2 also, should permit outside-inside telnet xfic.

Erick

Thanks for your response.

I do have telnet traffic permitted on PIX-2 and I can telnet fine after adding a static route to any of the workstations that I'm working off of. That is how I have been operating up until now. But I would think I should be able to add a static route to the gateway of 192.168.x.2 which would lead to the 10.0.x.0 network and this shoudl be on PIX-1... right?

Also... would is the ideal router for small networks with minimal routing such as the one I have been describing. I am essentially using the PIX firewalls as routers on all three networks.

In theory what you say is correct but in actuality it wont happen. Reason is that the Pix will not send it back out the same interface.

Traffic from 192.168.x.10 goes to Pix1 which has the route to 10.0.x.0 via 192.168.x.2 (Pix2 Outside) when the pix gets this it drops the packet because it violates the security design of the Pix.

Any "router" would do .. if you are looking cheap, Linux box, Linksys, *shudder* Windows.

rmeder
Community Member

Ahh... makes perfect sense! I guess I will be adding to the route tables of the workstations for the time being.

Can you recommend a cisco or equivelant router to be used in this situation? There are about 15-25 nodes on each network. The communication accross them will continue to be very minimal.

Thanks again for your assistance!

Rick