two VLANs end two  different PIXs as gateway

Posted on 2006-04-05
Last Modified: 2010-03-19
My LAN network is composed of 1 3560G catalyst switch used as a distribution where my routers, servers are connected and a 2950 catalyst switch used as access switch for computers and printers. A new company, composed of only 5 people, will soon merge with us but, as our internal policy, they will have to use a different gateway (PIX firewall) to go out internet. Both PIX firewall are connected to the 3560G but in two different VLANs. So the network will have:
VLAN1    gatway1/PIX1  IP:
VLAN2    gatway2/PIX2  IP:
My internal DNS is on VLAN1 (  , how can I configure PIX2 to resolve the domain-name using my internal DNS ? Do you think it`s better using the 3560G switch as L3 to route between the two VLANs or  the PIX works just fine for that? In case I use the PIX as L3, does it need to have two internal interfaces (besides the external to internet) on two different VLANs in order to route?

Thank you for help!!!!      
Question by:ggmisadmin
    LVL 3

    Accepted Solution

    Pix's have issues routing back internally.
    you are better off enabling IP routing on the 3560
    but be specific and only allow routes to the internal dns
    if you do not want both vlans to be fully meshed

    Author Comment

    Thank you for your replay.
    Does it means that people on Vlan2 need to have  vlan2 interface's  IP as default gateway? In that case how the switch know how to forward internet traffic to the PIX whose IP is ?
    Do I need to create an ACL such as: "access-list 100 permit udp any host eq 53" and apply this on Vlan2 interface?  Is that enought for allowing DNS-traffic?  

    Thank you!
    LVL 3

    Expert Comment

    yes you will need to enter the default gateways
    routing will take care of the traffic.
    there is no need for access-lists.

    However if you wish to increase security
    once traffic is routing correctly, add access-lists to limit the connectivity.


    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    How your wiki can always stay up-to-date

    Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
    - Increase transparency
    - Onboard new hires faster
    - Access from mobile/offline

    As dyndns has reduced the capabilities of the free service, I looked around for other free providers of Dynamic DNS service. After testing several I decided to move my DNS hosting to Hurricane Electric as then domains that require dynamic hostnam…
    Let’s list some of the technologies that enable smooth teleworking. 
    Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
    After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

    761 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    7 Experts available now in Live!

    Get 1:1 Help Now