Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations biv343 on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Source Address Routing

Status
Not open for further replies.

8873402

Technical User
Jan 24, 2004
8
US
Hi All,
We have 2 T1's terminating on their individual cisco router(which have 1 serial interface and 1 ethernet interface). A Cisco Pix Firewall is placed between the routers and the internal Machines.
My Question is how Can I translate the source address of any packet coming on the Serial interface of the cisco router to go to PIX Firewall, as though it is coming From Ethernet interface of the cisco router.
I need this because, then in the return packet the destination address of the packet will be cisco router's ethernet interface and PIX will route the packets to the Cisco Router from which the packet originated.
This way I am hoping to have 2 individual paths for internal Machines from the outside world thru' 2 different Routers.
Please Help
 
I have the WAN Address from ISP configured on my Serial 0/0.1 and one of my public IP Addresses configured on the Ethernet Interface.

WAN Address :- 199.230.123.254
Ethernet Address:- 216.68.40.1
 
Hi,
Here is a little more detail,

Router1:- Router2:-
Serial0/0.1:-199.230.123.254 Serial0/0.1:-144.156.177.254
Eth0/0:- 216.68.40.1 Eth0/0:- 65.155.168.1


Cisco PIX FIrewall
Outside Interface:- 65.155.168.2
Inside1 Interface:- 216.68.40.2
Inside Interface:- 10.0.0.1
Default Route on PIX:- 0.0.0.0 0.0.0.0 65.155.168.1

Inside Machine
eth0:- 10.0.0.13
External Addresses for this Machine are
216.68.40.5
65.155.168.5

So if I am on internet and I telnet to 216.68.40.5, the packet will reach the inside machine via router1 but will go out via router2.

I need some help in forcing this packet to go from whichever router the packet came from, and to me it sounds like the only way to do it will be, if pix sees that all the traffic is coming with source IP 216.68.40.1.

Thanks

 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top