Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

HELP PIX INTERNAL ROUTING!!!#@@#

Status
Not open for further replies.

evildik

MIS
Sep 2, 2003
39
US
Scenario is as follows


172.16.10.0 255.255.255.0
|
Router Internet
| |
VPN Router
| |
Netscreen PIX 515
| |
\ /
LAN
|
WORKSTATIONS


Netscreen 192.168.0.2
PIX 192.168.0.1

Everyone on the lan interface uses the PIX as the default router. For some reason when i add
route inside 172.16.10.0 255.255.0.0 192.168.0.2 1 to the pix the clients cannot get to the 172.16.10.0 subnet using the PIX to route internally to the netscreen.

But setting a internal route on the PIX should allow users to route to the netscreen firewall shouldn't it?

From the pix i can ping the netscreen.
From the workstations i can ping the pix and the netscreen
From the workstations by adding a static route locally on the workstation i can ping the remote network..


HELP SOMEONE?
 
No, pix cannot reroute or send icmp redirects. Use a router or your netscreen as def. gateway and point def. route to the pix in that.


Network Systems Engineer
CCNA/CQS/CCSP/Infosec
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top