Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations biv343 on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

nameif command not working?????

Status
Not open for further replies.

ixleplix

MIS
Feb 6, 2003
129
Here is my problem/scenario: I'm trying to set up a new
DMZ on my PIX 515 running 6.3(1) and I have a 4 port expansion card in the PIX. I allready have one DMZ running. It is
interface ethernet2 auto
nameif ethernet2 DMZ security50
ip address DMZ X.X.X.1 255.255.255.0
global (DMZ) 1 x.x.x.200-x.x.x.250
global (DMZ) 1 x.x.x.199
nat (DMZ) 1 x.x.x.0 255.255.255.0 0 0

So anyway, that one is working fine.
Now, when trying to configure ethernet3, after entering configuration mode

When I type int e3 auto the command is accepted
When I type nameif e3 SO sec75 I get the response
Usage: nameif <hardware_id> <if_name> <security_lvl>
nameif <vlan_id> <if_name> <security_lvl>
no nameif
The same thing happens no matter how carefully I spell the commands and whether or not they're abbreviated.......

Also, when I type show interface it lists e0, e1, and e2 but nothing after.....

Hopefully this is something simple that I'm overlooking and not a hardware issue.

Please Help!
Thank you;
Roland

1) A robot may not injure a human being or, through inaction, allow a human being to come to harm.

2) A robot must obey orders given it by human beings except where such orders would conflict with the First Law.

3) A robot must protect its own existence as long as such protection does not conflict with the First or Second Law.
 
Could this be a licensing issue? I know that the PIX has restricted and unrestricted licenses. The restricted license restricts the number of interfaces you can configure. What kind of license do you have?

Andy
 
Well, I hadn't thought to check the ability of the license to handle more than 3 interfaces, but once you mentioned it I ran show version and this is what I got.

Failover: Disabled
VPN-DES: Enabled
VPN-3DES-AES: Enabled
Maximum Interfaces: 3
Cut-through Proxy: Enabled
Guards: Enabled
URL-filtering: Enabled
Inside Hosts: Unlimited
Throughput: Unlimited
IKE peers: Unlimited

This PIX has a Restricted (R) license.

So thank you for pointing me in the right direction and %$^&!!@#$ *!!@#$$$#@!!!! to the sales rep who sold us the 4-port card without telling us that it would require aditional licensing to use more than one of the ports.
Thanks again,
Roland

1) A robot may not injure a human being or, through inaction, allow a human being to come to harm.

2) A robot must obey orders given it by human beings except where such orders would conflict with the First Law.

3) A robot must protect its own existence as long as such protection does not conflict with the First or Second Law.
 
Thats gonna be a pricey one, you need an unrestricted license for that.

Jan

Network Systems Engineer
CCNA/CQS/CCSP
 
Yeah, it's expensive enough that we are now looking at &quot;other options&quot;---Like implementing Vlans, and using more Acl's on the routers etc---....... Oh well, job security :)

Roland

1) A robot may not injure a human being or, through inaction, allow a human being to come to harm.

2) A robot must obey orders given it by human beings except where such orders would conflict with the First Law.

3) A robot must protect its own existence as long as such protection does not conflict with the First or Second Law.
 
btw, number of supported interfaces via vlan will be increased in version 7.0 of the pix sw.

Network Systems Engineer
CCNA/CQS/CCSP
 
Q2 this year i think it was...

Jan

Network Systems Engineer
CCNA/CQS/CCSP
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top