Advertisement

03.26.2008 at 04:29PM PDT, ID: 23272503 | Points: 500
[x]
Attachment Details

Configuring a Pix 515 as a Router

Tags: Cisco, Pix, 515
I got a Pix 515 with 6 port i want to use it as a router...

I have set my ip adress on interface i want to use and i set level of security at 0 to be equal every where...

I set Rip V2 on each interface and i cannot ping from one pc in Intf2 to Outside....
 
what i need to do if i want my network to talk each other without problem on any protocol...nothing block only a Router...



PIX Version 6.3(4)
interface ethernet0 auto
interface ethernet1 auto
interface ethernet2 auto
interface ethernet3 auto
interface ethernet4 auto
interface ethernet5 auto
nameif ethernet0 outside security0
nameif ethernet1 inside security100
nameif ethernet2 intf2 security0
nameif ethernet3 intf3 security0
nameif ethernet4 intf4 security0
nameif ethernet5 intf5 security0
enable password g3vEEd4RfX2v6ff2 encrypted
passwd 2KFQnbNIdI.2KYOU encrypted
hostname 9494-St-Laurent
domain-name visior
fixup protocol dns maximum-length 512
fixup protocol ftp 21
fixup protocol h323 h225 1720
fixup protocol h323 ras 1718-1719
fixup protocol http 80
fixup protocol rtsp 554
fixup protocol sip 5060
fixup protocol sip udp 5060
fixup protocol skinny 2000
fixup protocol smtp 25
fixup protocol sqlnet 1521
fixup protocol tftp 69
names
pager lines 24
mtu outside 1500
mtu inside 1500
mtu intf2 1500
mtu intf3 1500
mtu intf4 1500
mtu intf5 1500
ip address outside 192.168.210.2 255.255.255.0
no ip address inside
ip address intf2 x.x.x.1 255.255.255.248
ip address intf3 x.x.x.9 255.255.255.248
no ip address intf4
no ip address intf5
ip audit info action alarm
ip audit attack action alarm
failover timeout 0:00:00
failover poll 15
no failover ip address outside
no failover ip address inside
no failover ip address intf2
no failover ip address intf3
no failover ip address intf4
no failover ip address intf5
pdm history enable
arp timeout 14400
routing interface inside
rip outside default version 2
rip inside default version 2
rip intf2 default version 2
rip intf3 default version 2
rip intf4 default version 2
rip intf5 default version 2
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00
timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00
timeout uauth 0:05:00 absolute
aaa-server TACACS+ protocol tacacs+
aaa-server TACACS+ max-failed-attempts 3
rip intf5 default version 2
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00
timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00
timeout uauth 0:05:00 absolute
aaa-server TACACS+ protocol tacacs+
aaa-server TACACS+ max-failed-attempts 3
aaa-server TACACS+ deadtime 10
aaa-server RADIUS protocol radius
aaa-server RADIUS max-failed-attempts 3
aaa-server RADIUS deadtime 10
aaa-server LOCAL protocol local
no snmp-server location
no snmp-server contact
snmp-server community public
no snmp-server enable traps
floodguard enable
telnet timeout 5
ssh timeout 5
console timeout 0
terminal width 80
Cryptochecksum:7351433b1c6b500302bbf7258586d8e3
: end
Start your free trial to view this solution
Question Stats
Zone: Computer Hardware
Question Asked By: Jean-Pier
Question Asked On: 03.26.2008
Participating Experts: 3
Points: 500
Views: 0
Translate:
Loading Advertisement...
03.26.2008 at 05:14PM PDT, ID: 21217657

Rank: Master

All comments and solutions are available to Premium Service Members only.

Start your 7-day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
03.26.2008 at 05:19PM PDT, ID: 21217667

Rank: Sage

All comments and solutions are available to Premium Service Members only.

Start your 7-day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
03.26.2008 at 05:40PM PDT, ID: 21217754

Rank: Master

All comments and solutions are available to Premium Service Members only.

Start your 7-day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
03.26.2008 at 08:50PM PDT, ID: 21218404

Rank: Wizard

All comments and solutions are available to Premium Service Members only.

Start your 7-day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
03.27.2008 at 10:21AM PDT, ID: 21223784

Rank: Sage

All comments and solutions are available to Premium Service Members only.

Start your 7-day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
03.30.2008 at 11:06AM PDT, ID: 21241420

All comments and solutions are available to Premium Service Members only.

Start your 7-day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
03.30.2008 at 11:31AM PDT, ID: 21241481

Rank: Sage

All comments and solutions are available to Premium Service Members only.

Start your 7-day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
03.30.2008 at 11:59AM PDT, ID: 21241566

All comments and solutions are available to Premium Service Members only.

Start your 7-day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
03.30.2008 at 05:08PM PDT, ID: 21242467

Rank: Sage

All comments and solutions are available to Premium Service Members only.

Start your 7-day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.20.2008 at 07:53AM PDT, ID: 21606691

All comments and solutions are available to Premium Service Members only.

Start your 7-day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.21.2008 at 05:00AM PDT, ID: 21614061

Rank: Sage

All comments and solutions are available to Premium Service Members only.

Start your 7-day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
 
Loading Advertisement...
Microsoft
  • Internet Protocols
  • Applications
  • Development
  • OS
  • Hardware
  • Windows Security
Apple
  • Operating Systems
  • Hardware
  • Programming
  • Networking
  • Software
Internet
  • Search Engines
  • File Sharing
  • WebTrends / Stats
  • Spy / Ad Blockers
  • Web Browsers
  • New Net Users
  • Web Development
  • Chat / IM
  • Anti Spam
  • Web Servers
  • Anti-Virus
  • Email Clients
Gamers
  • Tips
  • Online / MMORPG
  • Puzzle
  • Emulators
  • Action / Adventure
  • Role Playing
  • Consoles
  • Game Programming
  • Strategy
  • Sports
  • Misc
  • Computer Games
Digital Living
  • Hardware
  • Automotive
  • New Net Users
  • New Users
  • Software
  • Digital Music
  • Gaming World
  • Home Security
  • Apple
  • Networking Hardware
Virus & Spyware
  • Vulnerabilities
  • IDS
  • Encryption
  • Anti-Virus
  • Operating Systems Security
  • Software Firewalls
  • WebApplications
  • Cell Phones
  • Operating Systems
  • Internet
  • Hardware Firewalls
Hardware
  • Displays / Monitors
  • Handhelds / PDAs
  • Components
  • Peripherals
  • Laptops/Notebooks
  • Servers
  • Misc
  • Apple
  • Embedded Hardware
  • Networking Hardware
  • Storage
  • Desktops
  • New Users
Software
  • System Utilities
  • Industry Specific
  • Network Management
  • Photos / Graphics
  • Page Layout
  • VMware
  • Misc
  • Web Development
  • OS
  • CYGWIN
  • Voice Recognition
  • Virtualization
  • Message Queue
  • Quality Assurance
  • Security
  • Firewalls
  • MultiMedia Applications
  • Development
  • Database
  • Office / Productivity
  • Business Management
  • OS/2 Apps
  • Server Software
  • Internet / Email
ITPro
  • OS
  • Storage
  • Encryption
  • Operating Systems Security
  • Apple Hardware
  • Laptops & Notebooks
  • Servers
  • Networking Hardware
  • Peripherals
  • Devices
  • Displays / Monitors
  • WebTrends / Stats
  • Search Engines
  • Firewalls
  • Web Computing
  • WebApplications
  • IDS
  • Vulnerabilities
  • Email Clients
  • File Sharing
  • Spy / Ad Blockers
  • Web Browsers
  • Web Servers
  • Networking
  • Anti-Virus
  • Consulting
  • Chat / IM
  • Anti Spam
Developer
  • Web Servers
  • Web Browsers
  • Game Programming
  • Dev Tools
  • Industry Specific
  • Office / Productivity
  • Database
  • CYGWIN
  • Web Development
  • Search Engines
  • File Sharing
  • WebTrends / Stats
  • Programming
  • Content Management
  • Application Servers
  • Protocols
Storage
  • Removable Backup Media
  • Storage Technology
  • Servers
  • Grid
  • Remote Access
  • Backup / Restore
  • Misc
  • Hard Drives
OS
  • Miscellaneous
  • Security
  • Development
  • Linux
  • VMware
  • MainFrame OS
  • Unix
  • Apple
  • OS / 2
  • AS / 400
  • BeOS
  • Microsoft
  • VMS / OpenVMS
Database
  • Oracle
  • Miscellaneous
  • MySQL
  • Software
  • Sybase
  • Contact Management
  • PostgreSQL
  • Data Manipulation
  • Clarion
  • InterSystems Cache
  • Siebel
  • MUMPS
  • OLAP
  • SQLBase
  • SAS
  • GIS & GPS
  • 4GL
  • Berkeley DB
  • DB2
  • Informix
  • Interbase / Firebird
  • FoxPro
  • Reporting
  • LDAP
  • Filemaker Pro
  • MS SQL Server
  • dBase
  • MS Access
Security
  • Misc
  • Web Browsers
  • Software Firewalls
  • Operating Systems Security
  • File Sharing
  • Spy / Ad Blockers
  • Vulnerabilities
  • WebApplications
  • IDS
  • Anti-Virus
  • Encryption
  • Anti Spam
  • Email Clients
  • VPN
  • Chat / IM
Programming
  • Editors IDEs
  • Installation
  • Handhelds / PDAs
  • Multimedia Programming
  • System / Kernel
  • Automation
  • Algorithms
  • Game
  • Signal Processing
  • Project Management
  • Open Source
  • Database
  • Misc
  • Languages
  • Processor Platforms
  • Theory
Web Development
  • Scripting
  • Blogs
  • Web Servers
  • Software
  • Search Engines
  • Web Graphics
  • Web Services
  • Images
  • Internet Marketing
  • Images and Photos
  • Components
  • Document Imaging
  • Web Languages/Standards
  • Illustration
  • WebApplications
  • Fonts
  • WebTrends / Stats
  • Authoring
  • Digital Camera Software
  • Miscellaneous
Networking
  • Protocols
  • Apple Networking
  • Network Management
  • Message Queue
  • Application Servers
  • Content Management
  • File Servers
  • Email Servers
  • Misc
  • Java Editors & IDEs
  • Wireless
  • Networking Hardware
  • Backup / Restore
  • System Utilities
  • ISPs & Hosting
  • Web Servers
  • Storage Technology
  • Removable Backup Media
  • Servers
  • Web Computing
  • Broadband
  • Grid
  • OS / 2
  • Novell Netware
  • Unix Networking
  • Windows Networking
  • Security
  • Telecommunications
  • Operating Systems
  • Linux Networking
Other
  • Lounge
  • Business Travel
  • Community Support
  • New Net Users
  • Philosophy / Religion
  • Math / Science
  • Miscellaneous
  • URLs
  • Expert Lounge
  • Politics
  • Puzzles / Riddles
  • Automotive
Community Support
  • Suggestions
  • New to EE
  • New Topics
  • CleanUp
  • Announcements
  • General
  • Feedback
  • Input
  • EE Bugs
 
03.26.2008 at 05:14PM PDT, ID: 21217657

Rank: Master

By default all traffic from a higher level security zone is passed to a lower level zone. So all traffic from your inside interface should already go to all other interfaces without out your intervention. For the other interfaces, you will want to apply access-lists on your interfaces that allow all traffic. To start you can try these

access-list 101 extended permit ip any any
access-list 101 extended permit icmp any any

You will then need to apply the access-list to your interfaces:
access-group 101 in interface intf2
access-group 101 in interface intf3
access-group 101 in interface intf4

Try that and see how it works for you. Just remember that the PIX is not technically a router and generally isn't used for one. I understand what you are trying to do, it just might not be as functional as you would like.
 
03.26.2008 at 05:19PM PDT, ID: 21217667

Rank: Sage

You will also need to change you security levels on the interfaces to be different from one another.  In the 6.x version of code on the PIX, interfaces with the same security level cannot talk to each other no matter how you have the ACL's configured.  Just make the the security levels something like 100, 80, 60, 40, 20, and 0 for the outside and then apply your ACL's.
 
03.26.2008 at 05:40PM PDT, ID: 21217754

Rank: Master

Thanks batry_boy!
I'm curious to hear how this works myself. I'm just wondering if we would need any nat 0/1 statements.
 
03.26.2008 at 08:50PM PDT, ID: 21218404

Rank: Wizard

For all the networks that terminate on the PIX, the routing would work with nat0 and different security levels. But not a suggested way of doing stuff, say if there is another network which is not directly connected and you expect the PIX to do the routing, ain't gonna work!

Cheers,
Rajesh
 
03.27.2008 at 10:21AM PDT, ID: 21223784

Rank: Sage

mkielar,

Rajesh is correct in his statements above.  To see how this works, take a look at the following example:

nameif ethernet0 outside security0
nameif ethernet1 inside security100
nameif ethernet2 intf2 security80
nameif ethernet3 intf3 security60
nameif ethernet4 intf4 security40
nameif ethernet5 intf5 security20

! NAT Exemption commands

nat (inside) 0 access-list nonat_inside
nat (intf2) 0 access-list nonat_intf2
nat (intf3) 0 access-list nonat_intf3
nat (intf4) 0 access-list nonat_intf4
nat (intf5) 0 access-list nonat_intf5

! NAT Exemption ACL's

access-list nonat_inside permit ip any any
access-list nonat_intf2 permit ip any any
access-list nonat_intf3 permit ip any any
access-list nonat_intf4 permit ip any any
access-list nonat_intf5 permit ip any any

! Traffic flow ACL's

access-list outside_access_in permit ip any any
access-list outside_access_in permit icmp any any
access-list intf2_access_in permit ip any any
access-list intf2_access_in permit icmp any any
access-list intf3_access_in permit ip any any
access-list intf3_access_in permit icmp any any
access-list intf4_access_in permit ip any any
access-list intf4_access_in permit icmp any any
access-list intf5_access_in permit ip any any
access-list intf5_access_in permit icmp any any

! Apply the traffic flow ACL's to the interfaces

access-group outside_access_in in interface outside
access-group intf2_access_in in interface intf2
access-group intf3_access_in in interface intf3
access-group intf4_access_in in interface intf4
access-group intf5_access_in in interface intf5

I used ACL's for the NAT exemption just to give some granularity of control over future NAT changes in case the administrator wants to change how the NAT exemption works without affecting too much traffic.

I would make one final statement that this is a very non-standard way of configuring the PIX.  I've never used the PIX as simply a L3 device like this, but I believe this scenario would work as outlined above.  I didn't lab this up at all, but this is how I would start out going about implementing this scenario.
 
03.30.2008 at 11:06AM PDT, ID: 21241420
Thx for your time and advise it was very helpfull ...
I had your code to my config but with this addon i cant ping from a computer connected in Outside to a Computer connected in Intf2...
I activated the debug command for Ping and ping dont cross pix from an interface to an other...

I will try some command...I'm waithing for your suggestion...

Thx a lot...
 
03.30.2008 at 11:31AM PDT, ID: 21241481

Rank: Sage

Please post your current running config and we'll have a look.
 
03.30.2008 at 11:59AM PDT, ID: 21241566
PIX Version 6.3(4)
interface ethernet0 auto
interface ethernet1 auto
interface ethernet2 auto
interface ethernet3 auto
interface ethernet4 auto
interface ethernet5 auto
nameif ethernet0 outside security0
nameif ethernet1 inside security100
nameif ethernet2 intf2 security80
nameif ethernet3 intf3 security60
nameif ethernet4 intf4 security40
nameif ethernet5 intf5 security20
enable password g3vEEd4RfX2v6ff2 encrypted
passwd 2KFQnbNIdI.2KYOU encrypted
hostname 9494-St-Laurent
domain-name xxx
fixup protocol dns maximum-length 512
fixup protocol ftp 21
fixup protocol h323 h225 1720
fixup protocol h323 ras 1718-1719
fixup protocol http 80
fixup protocol rtsp 554
fixup protocol sip 5060
fixup protocol sip udp 5060
fixup protocol skinny 2000
fixup protocol smtp 25
fixup protocol sqlnet 1521
fixup protocol tftp 69
names
access-list nonat_inside permit ip any any
access-list nonat_intf2 permit ip any any
access-list nonat_intf3 permit ip any any
access-list nonat_intf4 permit ip any any
access-list nonat_intf5 permit ip any any
access-list outside_access_in permit ip any any
access-list outside_access_in permit icmp any any
access-list intf2_access_in permit ip any any
access-list intf2_access_in permit icmp any any
access-list intf3_access_in permit ip any any
access-list intf3_access_in permit icmp any any
access-list intf4_access_in permit ip any any
access-list intf4_access_in permit icmp any any
access-list intf5_access_in permit ip any any
access-list intf5_access_in permit icmp any any
mtu outside 1500
mtu inside 1500
mtu intf2 1500
mtu intf3 1500
mtu intf4 1500
mtu intf5 1500
no ip address outside
ip address inside 192.168.210.2 255.255.255.0
ip address intf2 x.x.x.1 255.255.255.248
ip address intf3 x.x.x.9 255.255.255.248
no ip address intf4
no ip address intf5
ip audit info action alarm
ip audit attack action alarm
no failover
failover timeout 0:00:00
failover poll 15
no failover ip address outside
no failover ip address inside
no failover ip address intf2
no failover ip address intf3
no failover ip address intf4
no failover ip address intf5
arp timeout 14400
access-group outside_access_in in interface outside
access-group intf2_access_in in interface intf2
access-group intf3_access_in in interface intf3
access-group intf4_access_in in interface intf4
access-group intf5_access_in in interface intf5
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00
timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00
timeout uauth 0:05:00 absolute
aaa-server TACACS+ protocol tacacs+
aaa-server TACACS+ max-failed-attempts 3
aaa-server TACACS+ deadtime 10
aaa-server RADIUS protocol radius
aaa-server RADIUS max-failed-attempts 3
aaa-server RADIUS deadtime 10
aaa-server LOCAL protocol local
no snmp-server location
no snmp-server contact
snmp-server community public
no snmp-server enable traps
floodguard enable
telnet timeout 5
ssh timeout 5
console timeout 0
terminal width 80
Cryptochecksum:7969533f2b44f82110f60292be9a74f0
: end
 
03.30.2008 at 05:08PM PDT, ID: 21242467

Rank: Sage

Try adding this line and then ping from the outside to a host on intf2:

access-list intf2_access_in permit icmp any any echo-reply

You will probaby want to add that line to the other ACL's as well to let the ping replies come back...I thought that the "permit icmp any any" would take care of that, but I seem to remember trying that once before and I had to explicitly allow ICMP type "echo-reply".
 
05.20.2008 at 07:53AM PDT, ID: 21606691
Thx all for your time but its not working, I think i will drop this project and try something else...
Except if u have some idea how to do it...
 
05.21.2008 at 05:00AM PDT, ID: 21614061

Rank: Sage

I agree.  My suggestion would be to get a true router and be done with it.
 
 
20080236-EE-VQP-29 / EE_QW_2_20070628