Solved

create a route for certain destination IP's on inside of PIX 515e

Posted on 2004-03-29
11
1,057 Views
Last Modified: 2013-11-16
Hi,

I need your advice on this:

I have a local network (192.168.x.x) connecting to an ISP through a Cisco PIX515e (2 interfaces: inside and outside). This is working fine.

Now certain destination IP's need to be directed through a router on the local network (on the inside interface, I assume) .

How would I accomplish that? I would not like to change the local default gateway.

TIA

John
0
Comment
Question by:pworce
11 Comments
 
LVL 57

Expert Comment

by:Pete Long
ID: 10704021
Hello John, Im usure of your problem

you want some internal hosts to go through a router before they get to the pix?

if so just make the routers IP address the default gateway for the clients, and make the gateway of last resort of the router the IP of the PIX (internal IP that is)

Pete
0
 
LVL 57

Expert Comment

by:Pete Long
ID: 10704031
youve not got much choice. you CANNOT do routing with a pix firewall
0
 
LVL 57

Expert Comment

by:Pete Long
ID: 10704036
if that dont answer the question, your gonna need to give me some more info :)
0
 

Author Comment

by:pworce
ID: 10704127
I don't want to change the default gateway on the clients. Some external (destination) IP's need to be directed to another router.

I can't believe this can't be done.
There is a route cmd (6-24 command reference).

please advice ...
0
 
LVL 57

Expert Comment

by:Pete Long
ID: 10704182
Right I see

do this on one client to test

Start >run >cmd {enter}

route add <network number of DESTINATION NETWORK> mask <subnet mask of destination network> <ip address of the router> -p
0
Find Ransomware Secrets With All-Source Analysis

Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

 

Author Comment

by:pworce
ID: 10704313
Ok.

It did not find the gateway because it's on a class A network 10.x.x.x
0
 
LVL 57

Expert Comment

by:Pete Long
ID: 10704560
?? doesnt matter? from command line execute a   route print and post the results here :)
0
 

Author Comment

by:pworce
ID: 10704648
C:\Documents and Settings\user>route print
===========================================================================
Interfacelist
0x1 ........................... MS TCP Loopback interface
0x2 ...00 50 8b a5 af 3f ...... Compaq NC3161 Fast Ethernet NIC - Pakketplanner-
miniport
===========================================================================
===========================================================================
Activ routes:
Networkaddress             Netmask          Gateway       Interface  Metric
          0.0.0.0          0.0.0.0    192.9.200.254    192.9.200.47       30
        127.0.0.0        255.0.0.0        127.0.0.1       127.0.0.1       1
      192.9.200.0    255.255.255.0     192.9.200.47    192.9.200.47       30
     192.9.200.47  255.255.255.255        127.0.0.1       127.0.0.1       30
    192.9.200.255  255.255.255.255     192.9.200.47    192.9.200.47       30
        224.0.0.0        240.0.0.0     192.9.200.47    192.9.200.47       30
  255.255.255.255  255.255.255.255     192.9.200.47    192.9.200.47       1
default-gateway:     192.9.200.254
===========================================================================
Static routes:
  none

C:\Documents and Settings\user>
0
 
LVL 57

Expert Comment

by:Pete Long
ID: 10704753
OK heres me adding a 10. address to mine

C:\Documents and Settings\PeteLong>route add 10.2.2.0 mask 255.255.255.0 192.168.1.2 -p

C:\Documents and Settings\PeteLong>route print
===========================================================================
Interface List
0x1 ........................... MS TCP Loopback interface
0x2 ...00 01 03 c1 55 27 ...... 3Com EtherLink XL 10/100 PCI For Complete PC Man
agement NIC (3C905C-TX) - Packet Scheduler Miniport
===========================================================================
===========================================================================
Active Routes:
Network Destination        Netmask          Gateway       Interface  Metric
          0.0.0.0          0.0.0.0      192.168.1.1   192.168.1.100       20
         10.2.2.0    255.255.255.0      192.168.1.2   192.168.1.100       1
        127.0.0.0        255.0.0.0        127.0.0.1       127.0.0.1       1
      192.168.1.0    255.255.255.0    192.168.1.100   192.168.1.100       20
    192.168.1.100  255.255.255.255        127.0.0.1       127.0.0.1       20
    192.168.1.255  255.255.255.255    192.168.1.100   192.168.1.100       20
        224.0.0.0        240.0.0.0    192.168.1.100   192.168.1.100       20
  255.255.255.255  255.255.255.255    192.168.1.100   192.168.1.100       1
Default Gateway:       192.168.1.1
===========================================================================
Persistent Routes:
  Network Address          Netmask  Gateway Address  Metric
         10.2.2.0    255.255.255.0      192.168.1.2       1


Pete
0
 
LVL 79

Accepted Solution

by:
lrmoore earned 200 total points
ID: 10705591
If your PIX inside interface is 192.9.200.254  and it is the client's default gateway, adding a route statement on the PIX will not do you any good.

>I can't believe this can't be done.
Believe it. A PIX is NOT a router, it is a firewall. A firewall's job is to stop packets. A router's job is to forward packets.
A firewall will not re-direct a packet back out the same interface it came in on. If the source IP is on the inside interface, and you add a static route so that the destination IP is supposed to be re-directed to another host (router) on the inside interface, it just won't happen.

Either change the default gateway on the clients, or you will have to add  a static route to every client. If you forget to add the "-p" flag to make it permanent, the next time a client reboots, the route will be gone.

If this is a temporary setup, then you've created a lot of work for yourself.
If it is a permanent setup....
If you have any old router, you can use a "router on a stick" and use just one interface as the default gateway for your clients, and now you can forward any networks you want to wherever you want.
0
 
LVL 6

Expert Comment

by:Pascal666
ID: 10738854
If they are external IPs, why are they on your inside network?  Put the router in a DMZ off your PIX and you will be able to route to it.

-Pascal
0

Featured Post

Highfive + Dolby Voice = No More Audio Complaints!

Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

Join & Write a Comment

Suggested Solutions

There are many useful and sometimes not well documented or forgotten IOS or ASA/PIX commands. See IPE article here , there was also one on PacketU and on Cisco Tips & Tricks. Below are my favorites. I give also a few most often used for Cisco IPS an…
When I upgraded my ASA 8.2 to 8.3, I realized that my nonat statement was failing!   The log showed the following error:     %ASA-5-305013: Asymmetric NAT rules matched for forward and reverse flows It was caused by the config upgrade, because t…
This video shows how to remove a single email address from the Outlook 2010 Auto Suggestion memory. NOTE: For Outlook 2016 and 2013 perform the exact same steps. Open a new email: Click the New email button in Outlook. Start typing the address: …
This video demonstrates how to create an example email signature rule for a department in a company using CodeTwo Exchange Rules. The signature will be inserted beneath users' latest emails in conversations and will be displayed in users' Sent Items…

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now