connecting cisco 3550 to pix 515

Posted on 2003-10-29
Medium Priority
Last Modified: 2013-11-16
 I have 2 network connecting to centreal switch 3550
first network has switch (2950) at ip mask  gateway
secound network switch (2950) at ip mask  gateway 160.16..211.1

they are both connect to central switch  3550  ip mask
switch is set to ip routing

port 1 of 3550 ip set to   (wich connect to network1)
port 2 of 3550 ip set to   (wich connect to network2)

Now I want to connect pix firewall 515 to 3550 to permit 2 networks to access secure network
(pix inside interface ip of mask
(pix ouside interface ip of  mask (uncertain of this ...this is what was given to me)

I am uncertain of what gateway to give to central 3550 switch
in order to direct traffic wich is not destin for 160.16.209. and  160.16.211 to go to firewall

I guess i want to know if i should give gateway of central switch 3550  to ip of firewall and give gateway of inside interface of firewall to ip of central switch

Or do I creat a port on central switch  for example port 3 give it an ip of  and connect the firewall to it. give central switch gateway of  and also give gateway of firewall inside to

Or am I completly lost???


Question by:jerbell
  • 6
  • 4

Author Comment

ID: 9644891
Would it also be preferable that I don't assign port on central switch ip   and assign VLAN
Pros and Con???
LVL 13

Expert Comment

ID: 9647378
If you do as you say and give PIX inside IP of and the switch has an IP of then it will work fine.

On the PIX create routes to tell it how to get to your other two inside subnets:

route inside
route inside

which means that it will route any traffic for the two inside networks to the switch and then the switch will forward it to the networks.

Set the default route on the switch to be the IP of the PIX (


Author Comment

ID: 9647430
what do I give as the inside gateway?
Free recovery tool for Microsoft Active Directory

Veeam Explorer for Microsoft Active Directory provides fast and reliable object-level recovery for Active Directory from a single-pass, agentless backup or storage snapshot — without the need to restore an entire virtual machine or use third-party tools.

LVL 13

Expert Comment

ID: 9647506
do you mean for you two subnets ?

The default gateway for the two subnets is the IP of the L3 switch.

for devices on subnet, default gateway is
for devices on subnet, default gateway is

So all traffic will get sent to your L3 switch and it will tnhe forward it to the PIX (which is why it needs to have a default route pointing to the PIX IP)

Author Comment

ID: 9653376
traffic does not seem to flow from my 2 networks into the firewall when trying to access network on outside interface.

Seems like the central switch doesn't want to rout traffic there.

My 2 networks sees each other and sees central switch and can ping firewall

Firewall is connected to  port 24 of central switch.  Should that port be assign an ip?
I just assume if I assign the gateway of central switch to the ip of firewall that all traffic unknown to the central switch would flow into firewall (that is on same ip range as central switch).

Author Comment

ID: 9653606
here is firewall config ... hope somebody can help
interface ethernet0 auto                        
interface ethernet1 auto                        
nameif ethernet0 outside security0                                  
nameif ethernet1 inside security100                                  
hostname firewall                              
domain-name mydomain            
fixup protocol ftp 21                    
fixup protocol h323 h225 1720                            
fixup protocol h323 ras 1718-1719                                
fixup protocol http 80                      
fixup protocol ils 389                      
fixup protocol rsh 514                      
fixup protocol rtsp 554                      
fixup protocol sip 5060                      
fixup protocol sip udp 5060                          
fixup protocol skinny 2000                          
fixup protocol smtp 25                      
fixup protocol sqlnet 1521                          
name pcnet1                                                            
name pcnet2                                                    
name   servertoconnect                      
object-group network pcgroup                                
  description access to server                                                                                                      
  network-object pcnet1                                          
  network-object pcnet2                                            
access-list inside_access_in remark servertoconnect access                                              
access-list inside_access_in permit tcp object-group pcgroup host servertoconnect                                                            

 eq 102      
access-list inside_access_in remark testing pc rule                                                  
access-list inside_access_in remark testing pc rule                                                  
access-list inside_access_in remark testing pc rule                                                  
access-list inside_access_in remark testing pc rule                                                  
access-list acl_out permit icmp any any                                      
pager lines 24              
mtu outside 1500                
mtu inside 15            
ip address outside                                              
ip address inside                                            
ip audit info action alarm                          
ip audit attack action alarm                            
no failover          
failover timeout 0:00:00                        
failover poll 15                
no failover ip address outside                              
no failover ip address inside                            
pdm location inside                                                  
pdm location pcnet1 inside                                                
pdm location pcnet2 inside                                                                                    
pdm location servertoconnect outside                                              
pdm group pcgroup inside                            
pdm history enable                  
arp timeout 14400                
nat (inside) 0 0 0                                  
access-group acl_out in interface outside
access-group inside_access_in in interface inside
route inside 1
route outside servertoconnect 1
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00
timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00
timeout uauth 0:05:00 absolute
aaa-server TACACS+ protocol tacacs+
aaa-server RADIUS protocol radius
aaa-server LOCAL protocol local
http server enable
http inside
no snmp-server location
no snmp-server contact
snmp-server community public
no snmp-server enable traps
floodguard enable
telnet timeout 5
ssh timeout 5
console timeout 0
terminal width 80
LVL 13

Expert Comment

ID: 9654948
Ok, tests to try:

1. from PC with IP 160.16.209.x
a). ping
b). ping

2. from PC with IP 160.16.211.x, repeat two above tests

3. From 3550 switch, repeat above two tests.

If you don't get any responses, add the following:

access-list inside_access_in permit ip any any
access-list acl_out permit ip any any

and try again, just to make sure the ACL's aren't getting in the way.

Author Comment

ID: 9667795
I tried that but nothing seems to go to firewall!
I put a question on how to rout to firewall

Concept of routing and firewall seems so easy but yet a pain to figure out
LVL 13

Accepted Solution

td_miles earned 1500 total points
ID: 9668591
Even when you ping the PIX from 3550 switch you get no response ?

You could try as you suggested earlier and assign a specific port on the 3550 switch and give it an IP address As it already has an IP address in this subnet, I didn't think would have been necessary.

To make sure it is not anything in the PIX config, connect a PC to the same port that the PIX currently is and give it the same IP address of the PIX inside interface ( Now try pinging this IP address from the switch.

Could you also post your 3550 config, just to have a look over and make sure you have got the routing entered correctly.

Author Comment

ID: 9673593
thanks td_miles
The problem was in my central switch.
I had the default gateway assign to firewall but I had forgotten to set it up in default routing.
So what I did was set the default routing to point to firewall as well then everything worked.
Still unclear why they both have to be there.

Featured Post

Exciting career futures for women in IT

Education has the power to transform lives and open the door to new career opportunities. By earning an IT degree from WGU, you can become a highly skilled IT professional. Get the credentials and certifications you need to become a leader in this rewarding field.  

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Concerto Cloud Services, a provider of fully managed private, public and hybrid cloud solutions, announced today it was named to the 20 Coolest Cloud Infrastructure Vendors Of The 2017 Cloud  (http://www.concertocloud.com/about/in-the-news/2017/02/0…
Let’s face it: one of the reasons your organization chose a SaaS solution (whether Microsoft Dynamics 365, Netsuite or SAP) is that it is subscription-based. The upkeep is done. Or so you think.
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…
Suggested Courses

749 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question