I have pix 515E with a failover solution. I have all my internet traffic routed through the outside interface of the pix configuration. Right now we have got another ADSL Wan link and I need to route all internet traffic through this link. Can I simply configure a one of the extra interfaces...
If you have two wan links configured can how can you achieve the following.
1. Outside Interface - PAT all traffic except for WWW traffic inside network 172.20.0.0/16
2. Ousdside2 Interface - PAT all WWW traffic and deny all other traffice from the inside network 172.20.0.0/16
will...
I have a site office and its connected through a site-to-site vpn connection over a PIX501. Also the pix is used as the wan gateway that PAT an public IP for internet and VPN site to site connections. Is there anyway to give priority to the vpn connection. I don't want to spend too much...
Oh.. I have lots (lol). That is the problem, they want me to waste them. So its possible if I write sosmething like this even though my outside ip address is 14.62.31.yy3
(config t)# static (inside, outside) 14.62.31.xx1 172.16.4.22
pixfirewall (config t)# access-list internet permit tcp any...
Can you have two public ip's pointed to two private ips with but only the outside interface is configured with a public IP??? Will the outside interface pass traffic that does not have its public IP address to the inside if there is a access rule and a static statement?
Okay I think I did not explain the situation correctly. This is the setup. I have the outside interface configured with a IP from my ISP 209.113.15.666. I port translation going on for our webserver, and a smtp server and some other services inside. Now for some reason there is a another dns...
I have to configure two public IP's to a SMTP and a webserver. Port address translation is configured to ports, 80, 443, 110, etc. This extra SMTP server is registred with its own dns name webmail.company.com and the webserver is registred with another public IP address for its dns with...
Yes... this is possible. It will be something like this.. If the commands are not write just put "?" and adjust the commands.
global (outside) 1 interface
nat (inside) 1 0.0.0.0 0.0.0.0 0 0
static (inside,outside) tcp interface smtp 10.0.0.50 smtp netmask 255.255.255.255 0 0
static...
Actually I like the unit. I got a quote from them today. Can I send you email to your web site email address? I would like to see the price you can offer me? ;-). I am actually thinking of the top unit.
Thank you for the repply. Lets say if I get a router, do I need to have more than one interface for the different ISP lines? Any remondations with cisco routers for a medium size operation.
How can I direct web traffic from one wan link and all other traffic from another wan link? If the pix is attached to a switch and the switch has links from both ISP's to their gateways and if I create pat statements to achieve this, will this work?
The interface output I have displayed is the active (Primary) firewall. I have not connected them together yet. I want to get the two firewalls with their ip address. I am able to set the ip and communicate from the secondary (Standby) pix. It also has mac address. But the Primarry does not...
Thank you for the reply. I think the problem is with the Primary Failover PIX. Though I can assign it an ip address it does not have a mac address. When I debug arp I could see all the arp messages reaching the inside interface but it does not populate the arp table. The secondery firewall...
I have posted several posts here and tried to get a ping response from my PIX515E. I spent several hours with TAC and still no answer. Today I just discovered that my MAC address shows ffff.ffff.ffff. My silly question is that is this some security issue on the 515E?? I have another 515E...
I have a 515E pix and I can't seem to ping outside of it's inside interface to any host and host can't ping the inside interface of the pix. A Sonicwall is used as the gateway in the network right now. I am in the process of replacing it. The pix inside interface works fine if I directly...
I have configured the pix 515e inside interface with an IP address 172.20.1.200 255.255.0.0. I have connected to the device through the console port. Anyway I am able to ping the ip address of the inside interface from the pix console but unable to ping any ip from the pix in the same subnet...
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.