[2 days left] What’s wrong with your cloud strategy? Learn why multicloud solutions matter with Nimble Storage.Register Now


connecting cisco 3550 to pix 515

Posted on 2003-10-29
Medium Priority
Last Modified: 2013-11-16
 I have 2 network connecting to centreal switch 3550
first network has switch (2950) at ip mask  gateway
secound network switch (2950) at ip mask  gateway 160.16..211.1

they are both connect to central switch  3550  ip mask
switch is set to ip routing

port 1 of 3550 ip set to   (wich connect to network1)
port 2 of 3550 ip set to   (wich connect to network2)

Now I want to connect pix firewall 515 to 3550 to permit 2 networks to access secure network
(pix inside interface ip of mask
(pix ouside interface ip of  mask (uncertain of this ...this is what was given to me)

I am uncertain of what gateway to give to central 3550 switch
in order to direct traffic wich is not destin for 160.16.209. and  160.16.211 to go to firewall

I guess i want to know if i should give gateway of central switch 3550  to ip of firewall and give gateway of inside interface of firewall to ip of central switch

Or do I creat a port on central switch  for example port 3 give it an ip of  and connect the firewall to it. give central switch gateway of  and also give gateway of firewall inside to

Or am I completly lost???


Question by:jerbell
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 4

Author Comment

ID: 9644891
Would it also be preferable that I don't assign port on central switch ip   and assign VLAN
Pros and Con???
LVL 13

Expert Comment

ID: 9647378
If you do as you say and give PIX inside IP of and the switch has an IP of then it will work fine.

On the PIX create routes to tell it how to get to your other two inside subnets:

route inside
route inside

which means that it will route any traffic for the two inside networks to the switch and then the switch will forward it to the networks.

Set the default route on the switch to be the IP of the PIX (


Author Comment

ID: 9647430
what do I give as the inside gateway?
Are You Ready for GDPR?

With the GDPR deadline set for May 25, 2018, many organizations are ill-prepared due to uncertainty about the criteria for compliance. According to a recent WatchGuard survey, a staggering 37% of respondents don't even know if their organization needs to comply with GDPR. Do you?

LVL 13

Expert Comment

ID: 9647506
do you mean for you two subnets ?

The default gateway for the two subnets is the IP of the L3 switch.

for devices on subnet, default gateway is
for devices on subnet, default gateway is

So all traffic will get sent to your L3 switch and it will tnhe forward it to the PIX (which is why it needs to have a default route pointing to the PIX IP)

Author Comment

ID: 9653376
traffic does not seem to flow from my 2 networks into the firewall when trying to access network on outside interface.

Seems like the central switch doesn't want to rout traffic there.

My 2 networks sees each other and sees central switch and can ping firewall

Firewall is connected to  port 24 of central switch.  Should that port be assign an ip?
I just assume if I assign the gateway of central switch to the ip of firewall that all traffic unknown to the central switch would flow into firewall (that is on same ip range as central switch).

Author Comment

ID: 9653606
here is firewall config ... hope somebody can help
interface ethernet0 auto                        
interface ethernet1 auto                        
nameif ethernet0 outside security0                                  
nameif ethernet1 inside security100                                  
hostname firewall                              
domain-name mydomain            
fixup protocol ftp 21                    
fixup protocol h323 h225 1720                            
fixup protocol h323 ras 1718-1719                                
fixup protocol http 80                      
fixup protocol ils 389                      
fixup protocol rsh 514                      
fixup protocol rtsp 554                      
fixup protocol sip 5060                      
fixup protocol sip udp 5060                          
fixup protocol skinny 2000                          
fixup protocol smtp 25                      
fixup protocol sqlnet 1521                          
name pcnet1                                                            
name pcnet2                                                    
name   servertoconnect                      
object-group network pcgroup                                
  description access to server                                                                                                      
  network-object pcnet1                                          
  network-object pcnet2                                            
access-list inside_access_in remark servertoconnect access                                              
access-list inside_access_in permit tcp object-group pcgroup host servertoconnect                                                            

 eq 102      
access-list inside_access_in remark testing pc rule                                                  
access-list inside_access_in remark testing pc rule                                                  
access-list inside_access_in remark testing pc rule                                                  
access-list inside_access_in remark testing pc rule                                                  
access-list acl_out permit icmp any any                                      
pager lines 24              
mtu outside 1500                
mtu inside 15            
ip address outside                                              
ip address inside                                            
ip audit info action alarm                          
ip audit attack action alarm                            
no failover          
failover timeout 0:00:00                        
failover poll 15                
no failover ip address outside                              
no failover ip address inside                            
pdm location inside                                                  
pdm location pcnet1 inside                                                
pdm location pcnet2 inside                                                                                    
pdm location servertoconnect outside                                              
pdm group pcgroup inside                            
pdm history enable                  
arp timeout 14400                
nat (inside) 0 0 0                                  
access-group acl_out in interface outside
access-group inside_access_in in interface inside
route inside 1
route outside servertoconnect 1
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00
timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00
timeout uauth 0:05:00 absolute
aaa-server TACACS+ protocol tacacs+
aaa-server RADIUS protocol radius
aaa-server LOCAL protocol local
http server enable
http inside
no snmp-server location
no snmp-server contact
snmp-server community public
no snmp-server enable traps
floodguard enable
telnet timeout 5
ssh timeout 5
console timeout 0
terminal width 80
LVL 13

Expert Comment

ID: 9654948
Ok, tests to try:

1. from PC with IP 160.16.209.x
a). ping
b). ping

2. from PC with IP 160.16.211.x, repeat two above tests

3. From 3550 switch, repeat above two tests.

If you don't get any responses, add the following:

access-list inside_access_in permit ip any any
access-list acl_out permit ip any any

and try again, just to make sure the ACL's aren't getting in the way.

Author Comment

ID: 9667795
I tried that but nothing seems to go to firewall!
I put a question on how to rout to firewall

Concept of routing and firewall seems so easy but yet a pain to figure out
LVL 13

Accepted Solution

td_miles earned 1500 total points
ID: 9668591
Even when you ping the PIX from 3550 switch you get no response ?

You could try as you suggested earlier and assign a specific port on the 3550 switch and give it an IP address As it already has an IP address in this subnet, I didn't think would have been necessary.

To make sure it is not anything in the PIX config, connect a PC to the same port that the PIX currently is and give it the same IP address of the PIX inside interface ( Now try pinging this IP address from the switch.

Could you also post your 3550 config, just to have a look over and make sure you have got the routing entered correctly.

Author Comment

ID: 9673593
thanks td_miles
The problem was in my central switch.
I had the default gateway assign to firewall but I had forgotten to set it up in default routing.
So what I did was set the default routing to point to firewall as well then everything worked.
Still unclear why they both have to be there.

Featured Post

Q2 2017 - Latest Malware & Internet Attacks

WatchGuard’s Threat Lab is a group of dedicated threat researchers committed to helping you stay ahead of the bad guys by providing in-depth analysis of the top security threats to your network.  Check out our latest Quarterly Internet Security Report!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Use of TCL script on Cisco devices:  - create file and merge it with running configuration to apply configuration changes
You deserve ‘straight talk’ from your cloud provider about your risk, your costs, security, uptime and the processes that are in place to protect your mission-critical applications.
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Suggested Courses

649 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question