cisco pix 515e

Posted on 2006-04-01
Medium Priority
Last Modified: 2013-11-16
I need to know if my pix will support 2 ISPs, meaning if the primary ISP goes down the backup would take over, can this be done?
Question by:tstuardo
  • 2
  • 2
LVL 19

Accepted Solution

nodisco earned 1000 total points
ID: 16350555
Hi there

not specifically with a pix.  Outbound traffic to the internet goes out the outside interface on a pix and this interface cannot terminate an internet connection - let alone 2 of them.  You can of course have 2 ISPs and a PIX inside, but the edge routers are what do the work.  ie.

  ISP 1                             ISP 2
Edge router 1               Edge router 2
         Both sharing 1 ethernet address

Have BGP between both routers and you have full failover for ISPs

A simpler solution would be one edge router with 2 interfaces - one for each ISP.  In the event of one going down, you have the second connection to provide internet connectivity - as I said - a few ways of doing this.  But the pix does not care or know whether the ISPs circuit has gone down or not.  It has an ethernet connection to the edge router(s) and if the ISP link goes down, the pix won't know as the ethernet interface is still up.

heop this helps
LVL 79

Assisted Solution

lrmoore earned 1000 total points
ID: 16350570
Not with PIX by itself. I can only support one default gateway at a time.
However, it really depends on your connections to the ISP(s).
If you have, say, a T1 from ISPA and a T1 from ISPB, then I would assume you also have T1 Routers:

   ISPA               ISPB
     T1                  T1
   Router1          Router2
        |_ _ _______|
           PIX Outside

With this scenario, you have several choices. You can use dynamic routing protocols such as OSPF so that both routers and the PIX talk to each other and they all 3 know which T1 is up/available. Your dilema here will be which ISP's public IP address space are you using on the PIX outside? You can't use both, so perhaps Router2 does a double-nat . . .

If you have DSL or other ISP connections, or T1 and DSL then you have other problems that are not easy to overcome.   Can you better explain your external connections to your 2 ISP's ?

There are many dual-WAN capable firewalls on the market. The PIX is not one of them.
Linksys RV0x2 series
Linksys RV082:


Netgear FVS318

Zyxel Zywall

hot Brick - dual WAN

Watchguard Firebox


LVL 79

Expert Comment

ID: 16350576
LOL! Great minds think alike!
LVL 19

Expert Comment

ID: 16350608

Featured Post

2017 Webroot Threat Report

MSPs: Get the facts you need to protect your clients.
The 2017 Webroot Threat Report provides a uniquely insightful global view into the analysis and discoveries made by the Webroot® Threat Intelligence Platform to provide insights on key trends and risks as seen by our users.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

You deserve ‘straight talk’ from your cloud provider about your risk, your costs, security, uptime and the processes that are in place to protect your mission-critical applications.
This article is in regards to the Cisco QSFP-4SFP10G-CU1M cables, which are designed to uplink/downlink 40GB ports to 10GB SFP ports. I recently experienced this and found very little configuration documentation on how these are supposed to be confi…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Suggested Courses
Course of the Month15 days, 14 hours left to enroll

850 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question