Solved

PIX 501: Inside/Outside IP Addressing

Posted on 2006-11-17
2
341 Views
Last Modified: 2010-04-12
Hello!

Just to warn you before reading this: I barely know enough about subnetting to get by so excuse any stupid questions please. Anyway, I am trying to set up two network segments separated by my PIX. When I try and change the inside IP of the PIX I get an error:

pixfirewall(config)# show ip
System IP Addresses:
        ip address outside 172.20.4.9 255.255.252.0
        ip address inside 192.168.1.1 255.255.255.0
Current IP Addresses:
        ip address outside 172.20.4.9 255.255.252.0
        ip address inside 192.168.1.1 255.255.255.0
pixfirewall(config)# ip address inside 172.20.6.1 255.255.252.0
Sorry, not allowed to enter IP address on same network as interface 0

With a subnet mask of 255.255.252.0 isn't 172.20.4.X on a different subnet as 172.20.6.X? Why is there a conflict?

Thanks in advance.

Mike
0
Comment
Question by:jbisordi
  • 2
2 Comments
 
LVL 51

Accepted Solution

by:
Keith Alabaster earned 250 total points
ID: 17967421
You have used a 255.255.252.0 mask which includes both the outside ip range 172.20.4.0 and the suggested inside ip range of 172.20.6.0, you cannot do this. If you want to use these addresses then change the subnet mask to 255.255.255.0

the 255.255.252.0 mask = all addresses from 172.20.4.0 - 172.20.7.255
the 255.255.255.0 mask = 172.4.0 - 172.20.4.255

alternatively you could use 255.255.254.0

the 255.255.254.0 mask = 172.20.4.0 - 172.20.5.255

Whichever you choose, make sure that ALL devices on the subnets are changed to reflect the same subnet masks.

Regards
Keith
                                   
0
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 17967908
Thank you :)
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

When I upgraded my ASA 8.2 to 8.3, I realized that my nonat statement was failing!   The log showed the following error:     %ASA-5-305013: Asymmetric NAT rules matched for forward and reverse flows It was caused by the config upgrade, because t…
This article assumes you have at least one Cisco ASA or PIX configured with working internet and a non-dynamic, public, address on the outside interface. If you need instructions on how to enable your device for internet, or basic configuration info…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question