How to configure more than one default gateway on the PIX Firewall


Core issue

In some situations, it may be necessary to configure multiple default gateways on the PIX, either for load balance or for backup.  However, the PIX does not support load balancing and always uses the first default gateway configured. If you try to configure an additional default gateway on the same interface, or a different interface, the PIX Command-Line Interface (CLI) rejects the command, unless you use a different metric. Even then, the PIX only utilizes the first default gateway.


Since the PIX does not support multiple default gateways, use the Hot Standby Routing Protocol (HSRP). Configure HSRP on the various default gateway devices, and have the PIX default gateway statement reference the single HSRP virtual IP address.

