PIX Routing?

May 17, 2005 3 Replies
PIX Routing? open original image

Can someone explain the capabilities of the PIX with regards to routing? Seems to be very little information on the PIX route command both on Google and the Cisco web site.



Here's an example, we have 2 points of exit from our subnet, 1 is via the PIX and 1 is via a Watchguard. All clients use the PIX as their default gateway but we want traffic destined for certain subnets to exit via the Watchguard. It's my understanding that the PIX does not allow you to setup a route to tell the inside interface that if traffic shows up destined for 192.168.10.x, 192.168.20.x or 192.168.30.x, send it to the Watchguard. Is this a correct statement? I realize that an alternative is to setup a router in front of the PIX/Watchguard but I'm just trying to understand why the PIX cannot handle such a common task?



Thx. snipped-for-privacy@rocketmail.com



In article , wrote: :Can someone explain the capabilities of the PIX with regards to :routing? Seems to be very little information on the PIX route command :both on Google and the Cisco web site.

There isn't a lot to say about it ;-)

:Here's an example, we have 2 points of exit from our subnet, 1 is via :the PIX and 1 is via a Watchguard. All clients use the PIX as their :default gateway but we want traffic destined for certain subnets to :exit via the Watchguard. It's my understanding that the PIX does not :allow you to setup a route to tell the inside interface that if traffic :shows up destined for 192.168.10.x, 192.168.20.x or 192.168.30.x, send :it to the Watchguard. Is this a correct statement?

It is not correct under either of two circumstances:

a) that the path to the Watchguard is through a different physical or logical interface on the PIX [a logical interface is a VLAN, and you

*can* have logical interfaces on the "inside" physical interface];

b) that you are using PIX 7.0(1)

:I realize that an :alternative is to setup a router in front of the PIX/Watchguard but I'm :just trying to understand why the PIX cannot handle such a common task?

I think you will understand the situation better if you read through my posting of a few days ago,

formatting link

|Can someone explain the capabilities of the PIX with regards to |routing? Seems to be very little information on the PIX route command |both on Google and the Cisco web site. | |Here's an example, we have 2 points of exit from our subnet, 1 is via |the PIX and 1 is via a Watchguard. All clients use the PIX as their |default gateway but we want traffic destined for certain subnets to |exit via the Watchguard. It's my understanding that the PIX does not |allow you to setup a route to tell the inside interface that if traffic |shows up destined for 192.168.10.x, 192.168.20.x or 192.168.30.x, send |it to the Watchguard. Is this a correct statement? I realize that an |alternative is to setup a router in front of the PIX/Watchguard but I'm |just trying to understand why the PIX cannot handle such a common task? | |Thx. snipped-for-privacy@rocketmail.com

If you setup route tables on each local system this works great. We have a T1 and cable modem in one of our office but the T1 provider doesn't provide NNTP access so I use the Route command (they're all Windows systems) to tell it all traffic destined for the IP of the NNTP server go out through the 501 attached to the cable modem (the T is on a 506E). You can add these via a startup script to each system at logon so changing them is as simple as log off and back on.

Thanks... Brian Bergin

I can be reached via e-mail at cisco_dot_news_at_comcept_dot_net.

Please post replies to the group so all may benefit.

NOTICE: Use of this information is contingent upon acceptance of Paragraph 17 of Terabyte's Terms and conditions located at

formatting link

Even with 7.0(1) software the PIX won't redirect non-encrypted traffic. That feature only works if the packet arrives at the PIX via an IPSec tunnel, either site-to-site or remote client.

HTH

Walter Robers> > :Can someone explain the capabilities of the PIX with regards to

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required