Solved

Pix problem

Posted on 2003-10-21
13
687 Views
Last Modified: 2013-11-16
I jut got in a new Pix 501 and am having a problem. I want to change the IP addresses of both the outside interface and the inside interface. I can change the outside IP address fine, but after I change the inside interface and save I lose connection. I am then unable to connect to the admin interface using the new IP address even though I have given my address range permissions to use the web based admin console. What am I missing?
0
Comment
Question by:MrWhitefolks
  • 3
  • 3
  • 2
  • +3
13 Comments
 
LVL 2

Expert Comment

by:sh00t3r
ID: 9595149
1. Make sure your typing in https, not http
2. You may have to add http functionality on the edited interface.

whoop gotta run brb
0
 
LVL 13

Expert Comment

by:td_miles
ID: 9596059
can you ping the new IP address after you change it ?
0
 
LVL 2

Expert Comment

by:TomCRiley
ID: 9598370
How are you connected to the PIX when you try to change the inside interface IP?  If not via a console cable, that would explain your troubles.
0
 

Author Comment

by:MrWhitefolks
ID: 9598507
I am connected via ethernet cable and change the interface via HTTPS. Once I get it changed I am able to ping the new ip address, so I know the change worked,  but I can not get the admin console to display. I am typing httpS://
0
 

Author Comment

by:MrWhitefolks
ID: 9599522
Also I disabled DHCP on the inside interface and deleted the address range that was listed. Do I need to add a new network under the hosts/networks tab? because I did add 10.20.0.0 / 255.255.0.0 (int) inside.
0
 
LVL 4

Expert Comment

by:Kokoglen
ID: 9599885
I bought a pix not too long ago for the first time. (What a horrible mistake).
I changed a setting like you are talking about and lost internet access.
The cisco engineer told me to turn off the router and turn it back on.  (Power cycle it) and that worked.  I couldnt believe it, what mickey mouse crap was that??  There was no command to fix it, just turn it off and turn it on.

Im not sure if this will fix your problem, but I needed to vent.  And if it does fix it.  Well, there you go. ;)
0
Find Ransomware Secrets With All-Source Analysis

Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

 
LVL 2

Expert Comment

by:TomCRiley
ID: 9600277
That's one of the silliest things I've heard in a while.
0
 
LVL 2

Expert Comment

by:sh00t3r
ID: 9600596
Make sure to clear your temp internet files and cookies!!!
0
 
LVL 79

Accepted Solution

by:
lrmoore earned 50 total points
ID: 9609175
Also, did you include http access to the new subnet before you changed it?

i.e.

http inside <new subnet> <mask>
0
 
LVL 79

Expert Comment

by:lrmoore
ID: 9609321
By the way, having to reboot is not silly. It clears the arp cache. Otherwise, you still have an arp table that holds the old IP address to the MAC addresses of the workstations...
Techs often find it easier to say "reboot" than to walk someone through clearing the arp cache and try to explain what it all means..

My syntax was inorrect in my last post:

you should see something like:

http <old subnet> <mask> inside

and you need to add
http <new subnet> <mask> inside

0
 
LVL 2

Expert Comment

by:TomCRiley
ID: 9609368
lrmoore,

Thanks for the lesson on arp cache but that wasn't the silly part.  Saying that buying a PIX was a mistake and that the reload was mickey mouse crap just because he doesn't know how to use it was the silly part.
0
 
LVL 79

Expert Comment

by:lrmoore
ID: 9609443
agree. There is nothing micky-mouse about a PIX...

- Cheers!
0
 
LVL 4

Expert Comment

by:Kokoglen
ID: 9609499
The pix is a mistake for anyone who wants to use a GUI only.  I stand by that statement.  Ive worked with Sonicwall and it never needed to be rebooted to clear anything.  So a cisco engineer saying to reboot rather than go through (how many commands does it take) the process of clearing the cache is retarded.

Try using the pix from scratch for a real setup without the command line.  Its alomost impossible.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Join & Write a Comment

Cisco Pix/ASA hairpinning The term, hairpinning, comes from the fact that the traffic comes from one source into a router or similar device, makes a U-turn, and goes back the same way it came. Visualize this and you will see something that looks …
This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
It is a freely distributed piece of software for such tasks as photo retouching, image composition and image authoring. It works on many operating systems, in many languages.
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now