Pix and routes

Posted on 2005-03-03
Medium Priority
Last Modified: 2013-11-16

have a question about pix and routing to other vlans.

I have a catalyst 3750 behind a pix 525. The catalyst has several vlans configured. The
pix is connected to vlan 110. I need to give an outside user access to another vlan ( vlan 120 ).
How do i get the outside user routed to the other vlan.  

vlan 110
vlan 120
Question by:martyboy
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
LVL 57

Expert Comment

by:Pete Long
ID: 13447675
Firewalls cant route - you need to fire all traffic needing routing to a router (or a layer 3 switch if we are talking VLans)- using the "default route" command

Expert Comment

ID: 13447797
Ofcourse you PIX can route. Every firewall that I work with can route and my experience on firewalls are netscreen, nokia(checkpoint), PIX, stonegate, Symantec, iptables
The question is what type of access you need for that user. And is you firewall connected with another interface to that VLAN?

Author Comment

ID: 13447888
my inside interface is connected to the vlan switch. On that vlan switch a have 5 different lans configured. Now i need
and source from the outside to connect to my client vlan.

The answer is no, only interface connected to the switch is the inside interface.  After that i need to
route the traffic forward. The thing that i cant figure out is how to route the traffic after i setup the static command.
Maybe this wont work

Pete, the catalyst is a L3 device and is already routing traffic.
Bringing Advanced Authentication to the SMB Market

WatchGuard announces the acquisition of advanced authentication provider, Datablink, with one mission – to bring secure authentication to SMB, mid-market, and distributed enterprises with a cloud-based solution, ideal for resale via their established channel & MSSP community.


Accepted Solution

bloemkool1980 earned 750 total points
ID: 13447942
If you placed a static route to the gateway that knows address it should work.
Are you sure your switch allows to route traffic on that port to access both vlans?
THe problem is not on your firewall but on your switch

Author Comment

ID: 13448821
Thx bloem!

Actually everything was correct on the switch and pix. My static line on the pix
was wrong. When i reconfigured the static everything worked great.
LVL 79

Expert Comment

ID: 13448830
Yes, it will work.
Do you have a static route on the PIX

 route inside 192.168.1.x  (X=switch vlan 110 IP address)

Do you have a default on the switch that points to the PIX?
  ip route 192.168.1.y  (Y=PIX inside IP)


Expert Comment

ID: 13448857
Your welcome

Featured Post

Enroll in August's Course of the Month

August's CompTIA IT Fundamentals course includes 19 hours of basic computer principle modules and prepares you for the certification exam. It's free for Premium Members, Team Accounts, and Qualified Experts!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…
Suggested Courses
Course of the Month13 days, 15 hours left to enroll

800 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question