Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Pix Internal Routing

Status
Not open for further replies.

evildik

MIS
Sep 2, 2003
39
US
Scenario is as follows
192.168.10.0
|
Router Internet
| |
VPN Router
| |
Netscreen PIX 515
| |
LAN


Netscreen 192.168.0.2
PIX 192.168.0.1

Everyone on the lan interface uses the PIX as the default router. For some reason when i add
route inside 192.168.10.0 255.255.0.0 192.168.0.2 1 to the pix the clients cannot get to the 192.168.10.0 subnet using the PIX to route internally to the netscreen.

I am assuming that this is because the PIX cannot route packets on the same interface. Is this correct?
 
Correct, the PIX will not route packets back out the same interface.
 
But setting a internal route on the PIX should allow users to route to the netscreen firewall shouldn't it?

From the pix i can ping the netscreen.
From the workstations i can ping the pix and the netscreen
From the workstations by adding a static route i can ping the remote network..

 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top