create a route for certain destination IP's on inside of PIX 515e


I need your advice on this:

I have a local network (192.168.x.x) connecting to an ISP through a Cisco PIX515e (2 interfaces: inside and outside). This is working fine.

Now certain destination IP's need to be directed through a router on the local network (on the inside interface, I assume) .

How would I accomplish that? I would not like to change the local default gateway.


Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Pete LongTechnical ConsultantCommented:
Hello John, Im usure of your problem

you want some internal hosts to go through a router before they get to the pix?

if so just make the routers IP address the default gateway for the clients, and make the gateway of last resort of the router the IP of the PIX (internal IP that is)

Pete LongTechnical ConsultantCommented:
youve not got much choice. you CANNOT do routing with a pix firewall
Pete LongTechnical ConsultantCommented:
if that dont answer the question, your gonna need to give me some more info :)
The Firewall Audit Checklist

Preparing for a firewall audit today is almost impossible.
AlgoSec, together with some of the largest global organizations and auditors, has created a checklist to follow when preparing for your firewall audit. Simplify risk mitigation while staying compliant all of the time!

pworceAuthor Commented:
I don't want to change the default gateway on the clients. Some external (destination) IP's need to be directed to another router.

I can't believe this can't be done.
There is a route cmd (6-24 command reference).

please advice ...
Pete LongTechnical ConsultantCommented:
Right I see

do this on one client to test

Start >run >cmd {enter}

route add <network number of DESTINATION NETWORK> mask <subnet mask of destination network> <ip address of the router> -p
pworceAuthor Commented:

It did not find the gateway because it's on a class A network 10.x.x.x
Pete LongTechnical ConsultantCommented:
?? doesnt matter? from command line execute a   route print and post the results here :)
pworceAuthor Commented:
C:\Documents and Settings\user>route print
0x1 ........................... MS TCP Loopback interface
0x2 ...00 50 8b a5 af 3f ...... Compaq NC3161 Fast Ethernet NIC - Pakketplanner-
Activ routes:
Networkaddress             Netmask          Gateway       Interface  Metric
       30       1       30       30       30       30       1
Static routes:

C:\Documents and Settings\user>
Pete LongTechnical ConsultantCommented:
OK heres me adding a 10. address to mine

C:\Documents and Settings\PeteLong>route add mask -p

C:\Documents and Settings\PeteLong>route print
Interface List
0x1 ........................... MS TCP Loopback interface
0x2 ...00 01 03 c1 55 27 ...... 3Com EtherLink XL 10/100 PCI For Complete PC Man
agement NIC (3C905C-TX) - Packet Scheduler Miniport
Active Routes:
Network Destination        Netmask          Gateway       Interface  Metric
       20       1       1       20       20       20       20       1
Default Gateway:
Persistent Routes:
  Network Address          Netmask  Gateway Address  Metric       1

If your PIX inside interface is  and it is the client's default gateway, adding a route statement on the PIX will not do you any good.

>I can't believe this can't be done.
Believe it. A PIX is NOT a router, it is a firewall. A firewall's job is to stop packets. A router's job is to forward packets.
A firewall will not re-direct a packet back out the same interface it came in on. If the source IP is on the inside interface, and you add a static route so that the destination IP is supposed to be re-directed to another host (router) on the inside interface, it just won't happen.

Either change the default gateway on the clients, or you will have to add  a static route to every client. If you forget to add the "-p" flag to make it permanent, the next time a client reboots, the route will be gone.

If this is a temporary setup, then you've created a lot of work for yourself.
If it is a permanent setup....
If you have any old router, you can use a "router on a stick" and use just one interface as the default gateway for your clients, and now you can forward any networks you want to wherever you want.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
If they are external IPs, why are they on your inside network?  Put the router in a DMZ off your PIX and you will be able to route to it.

It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Software Firewalls

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.