PIX Firewall routing

View: New views
7 Messages — Rating Filter:   Alert me  

PIX Firewall routing

by Trond Kringstad :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Some parts of this message have been removed. Learn more about Nabble's security policy.
Hi,
I'm trying to let a PIX do routing inside into an internal router.
Could anyone answer me if this is possible?
 

Regards,

 

Trond


Parent Message unknown re: PIX Firewall routing

by Joseph Finley :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Some parts of this message have been removed. Learn more about Nabble's security policy.
# route inside NETWORK netmask ROUTERIP 2



From: Trond Kringstad <Trond@...>
Sent: Thursday, May 24, 2007 2:04 PM
To: "firewalls@..." <firewalls@...>
Subject: PIX Firewall routing


Hi,
I'm trying to let a PIX do routing inside into an internal router.
Could anyone answer me if this is possible?
 

Regards,

 

Trond



RE: PIX Firewall routing

by Michael Diana :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Some parts of this message have been removed. Learn more about Nabble's security policy.

Depends on what you are specifically trying to do, but you can and you have your choice of:

 

RIP

OSPF

and Static routes

 

Keep in mind, routing isn't the PIX's specialty.  It can get tricky with translations and access-rules.  the simpler the better.

 

Michael

 


From: listbounce@... [mailto:listbounce@...] On Behalf Of Trond Kringstad
Sent: Thursday, May 24, 2007 1:50 PM
To: firewalls@...
Subject: PIX Firewall routing

 

Hi,

I'm trying to let a PIX do routing inside into an internal router.

Could anyone answer me if this is possible?

 

Regards,

 

Trond


Re: PIX Firewall routing

by Security Guy :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Of course:

PIX 7.2 (applies to ASA too):
http://www.cisco.com/en/US/products/ps6120/products_configuration_guide_chapter09186a00806403ec.html

http://www.cisco.com/en/US/products/ps6120/products_command_reference_chapter09186a008063f0fa.html#wp1654829

PIX 6.3 (last of the 520, 515 506 series):

http://www.cisco.com/en/US/docs/security/pix/pix63/configuration/guide/bafwcfg.html

Or use ASDM to configure it.


On 5/24/07, Trond Kringstad <Trond@...> wrote:

>
>
> Hi,
> I'm trying to let a PIX do routing inside into an internal router.
> Could anyone answer me if this is possible?
>
>
>
> Regards,
>
>
>
> Trond


--
--

Lasciate ogne speranza, voi ch'intrate

RE: PIX Firewall routing

by Tim McLaurin :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Yes.  Using RIP or OSPF you can.  With the next release you can use EIGRP as well.  

________________________________

From: listbounce@... on behalf of Trond Kringstad
Sent: Thu 5/24/2007 1:50 PM
To: firewalls@...
Subject: PIX Firewall routing


Hi,
I'm trying to let a PIX do routing inside into an internal router.
Could anyone answer me if this is possible?
 
Regards,

 

Trond


Re: PIX Firewall routing

by Andrea Gatta :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Hi Trond,
course you can.
As far as I remember Cisco PIX supports static and dynamic routing
(starting from 6.3) as well. That is - you can configure PIX to run
OSPF. But be aware
that some restriction apply. Maybe Cisco ASA have a better OSPF support
but I would need to doublecheck.

As a reference have a look to this simple deployment at:

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00804acfea.shtml

Cheers,
Andrea

Trond Kringstad wrote:

> Hi,
> I'm trying to let a PIX do routing inside into an internal router.
> Could anyone answer me if this is possible?
>  
>
> Regards,
>
>  
>
> Trond
>


Re: PIX Firewall routing

by Prabhu Gurumurthy :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Trond Kringstad wrote:

> Hi,
> I'm trying to let a PIX do routing inside into an internal router.
> Could anyone answer me if this is possible?
>  
>
> Regards,
>
>  
>
> Trond
>

Remember PIX cannot do icmp redirects, which you will need if you multiple
routers and with PIX being the default route.

Prabhu
-