Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Westi on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

In defiance of logic.

Status
Not open for further replies.

N0ktar

Technical User
Jul 23, 2001
554
US
Pix 501 IOS v6.1 has been recently upgraded to v6.3. Cool, it went as smooth as the baby face. A week later we're changing the IP block, we're getting a bigger subnet so we need to reconfigure Pix. Now the fun part - I changed the addresses on the box (outside int, global and route outside) to reflect the change - and the pix refuses to work. I mean a real strange thing; it simply won't allow internet access (clear arp, clear xlate, rebooted as well). I even cleared the config and reconfigured from grounds up a couple times, still to no avail.
I can't post a config right now but in simplest words here's a process outline that fails to deliver:

pix# int eth0 10baset
pix# int eth1 100full
pix# nameif eth0 out security0
pix# nameif eth1 ins security100
pix# ip address inside 10.1.10.10
pix# ip address outside 208.x.x.x
pix# nat 1 0 0 0 0
pix# global 1 208.x.x.x
pix# route outside 0 0 208.x.x.x 1
pix# wr mem

now that basic config should allow internal hosts the internet access but it doesn't, have I missed something?
 
How about external router? Did you clear the arp cache on that?

-gbiello
 
Yes, let me add that the connection is fully functional. I plugged in my laptop, gave it a public IP, bypassed the firewall and I can get online.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top