Solved

Cisco Pix 506E w/PIX 6.3 and Transit Lan?

Posted on 2003-10-22
3
436 Views
Last Modified: 2013-11-16
I am setting up a few CoLocated servers at a new ISP, and they have a network configuration I have never seen before.

I have been assigned two networks for connectivity.  The first network is called the "Transit LAN" and consists of 2 IP addresses and is used to communicate with the router.
The second network is called the "customer LAN" and is useable by the my machines.
I need to create a virtual interface on the outside interface of the 506E with the "Transit LAN" information in order to get the 506E online.

They provide examples of how this works with Linux, Windows, etc (and it works).

Basically, I need to have interface ethernet0 have 2 IP addresses, 1 for the IP address that will be the REAL IP and one that is on the transit LAN.

How can I make ethernet0 have a virtual IP address on a 506E with PIX 6.3?








0
Comment
Question by:rxchurch
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 79

Expert Comment

by:lrmoore
ID: 9609125
Use the transit LAN ip as your outside interface, and use the Customer LAN as your NAT pool/static NAT addresses. That's all you really have to do.

Unless I mis-read the issue and you have both a router and a PIX.
In that case the "transit" LAN IP goes on the 'wan' interface of the router, the Customer LAN goes on the inside router interface, and the outside PIX interface, and the remainder is used as NAT Pool/static nat...

Use a private IP address space on the inside of the PIX

You can't do "virtual" interfaces or secondary addressing on the PIX
0
 

Author Comment

by:rxchurch
ID: 9615453
Thanks lrmoore.  You didn't read it incorrectly, I don't have a router.

This did get me connectivity for my LAN, but introduced a new problem.

What I didn't mention is that the "Transit" IP is not "useable" by us.  My ISP filters all TCP/UDP connections to this "Transit" IP at the router, but they allow ICMP for monitoring.
 So now I can ping the Transit IP, but I can't get an ssh connection.

Or more importantly, a VPN connection.

Any clue as how I can fix this problem?

0
 
LVL 79

Accepted Solution

by:
lrmoore earned 500 total points
ID: 9616232
OK. So the problem is that you need to remotely manage this PIX, and with the transit IP assigned to the external interface, you can't access it.
I suppose you can't VPN to it either....
Solution 1 - put a router in front of it....this way you actually go "through" the "transit" LAN and connect directly to the PIX interface with a Customer LAN IP...
Solution 2 - convince the ISP to provide SSH/HTTPS access to that IP
Solution 3 - use static NAT map to a server on the inside, use Terminal services to connect to the server, then use the server to connect to the inside IP of the PIX..

PIX just doesn't behave the same as a router, so no additional IP addresses, no virtual (loopback) addresses, and you can't connect to the internal interface from outside... options are limited..
0

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
For months I had no idea how to 'discover' the IP address of the other end of a link (without asking someone who knows), and it drove me batty. Think about it. You can't use Cisco Discovery Protocol (CDP) because it's not implemented on the ASAs.…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question