Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

HELP WITH INTERNAL ROUTING ON PIX!!!

Status
Not open for further replies.

evildik

MIS
Sep 2, 2003
39
US
Scenario is as follows


192.168.10.0
|
Router Internet
| |
VPN Router
| |
Netscreen PIX 515
| |
\ /
LAN
|
WORKSTATIONS


Netscreen 192.168.0.2
PIX 192.168.0.1

Everyone on the lan interface uses the PIX as the default router. For some reason when i add
route inside 192.168.10.0 255.255.0.0 192.168.0.2 1 to the pix the clients cannot get to the 192.168.10.0 subnet using the PIX to route internally to the netscreen.

But setting a internal route on the PIX should allow users to route to the netscreen firewall shouldn't it?

From the pix i can ping the netscreen.
From the workstations i can ping the pix and the netscreen
From the workstations by adding a static route locally on the workstation i can ping the remote network..


HELP SOMEONE?
 
Hi,

As I see, you are using subnet mask for remote network as 255.255.0.0.

Which means that you local network 192.168.0.0 and remote network 192.168.10.0. is in same subnet.

I think that good to be one of the reasons

 
I apologize the remote subnet is not 192.168.10.0 lets use 172.16.10.0 255.255.0.0
 
The Pix will not route 'on a stick'. Traffic entering one interface must be forwared through a different interface and not back through the same one.

Chris.

**********************
Chris A.C, CCNA, CCSA
**********************
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top