Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Inside/outside IP on same network

Status
Not open for further replies.
Jan 8, 2004
19
US
Long story as to the why, but ISP and client have made the situation to arise.

Customer connects to ISP via ethernet:
Internal-->PIX-->ISP-->internet

Does anyone know of a way to have both the inside and outside networks on the same subnet? I know this isnt the most secure and it disables part of what a firewall does, NAT. But, while I get the political side of it squared away, does anyone know if you can acomplish this on a pix?

I've seen other firewalls do it, Sonicwall, Netscreen...

Can anyone help?

TIA
 
What I meant in my previous post was... what type of PIX are you running and what version IOS?
 
It isn't possible. If you try to set your inside IP address to the same subnet as your outside IP address it'll give you this error.

Sorry, not allowed to enter IP address on same network as interface 0

I've tried it before. What are you trying to accomplish?
 
You are looking for layer 2 capabilities, which teh PIX currently does not support. The rumor is layer 2 capability will be a part of PIX OS 7, which is due out later this year.
 
We actually have our PIX inside/outside interfaces on the same class "B" network (not subnet). We're able to do this because our outside interface goes to our border router and is connected with point-to-point addresses. The inside interface connects to a core switch. We use route (inside) and route (outside) statements to move traffic.
 
Thanks for all the help guys. I was able to convince them to use NAT to protect their non-critical servers even further.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top