troubleshooting Question

PIX 501 fails to connect to ISP through wireless router

Avatar of sara_bellum
sara_bellumFlag for United States of America asked on
Software FirewallsCisco
25 Comments3 Solutions610 ViewsLast Modified:
Here is my network topology:

  DSL ---->  Linksys Wireless Router ----->     PIX 501              -------> PC2 (192.168.x.z)
bridge          (eth0)         (eth1)                 (eth0)     (eth1)
mode           1.2.3.4        1.2.6.7                1.2.6.8   192.168.x.y
                                        |
                                        |
                                      PC1
                                    1.2.6.9

1.2.3.4 is the fixed IP address assigned by my ISP for the PPPoE connection, which is now hosted on the wireless router.  The PIX can connect to the wireless router (eth1) at 1.2.6.7, but it doesn't get an icmp reply from the router's outside address at 1.2.3.4 unless I:
a) specify the outside interface of the PIX in my ping request or
b) add a route to 1.2.3.4 in the PIX config file  
When I add a route to 1.2.3.4, the PIX can ping 1.2.3.4 in the usual way and get a response, but it gets no icmp reply from the ISP gateway at 1.5.1.1, even after I add an additional route to the gateway.

Here are the relevant parts of my current PIX config, which is running Version 6.3(4) IOS:

global (outside) 1 interface
nat (inside) 1 192.168.x.0 255.255.255.0 0 0
nat (inside) 1 0.0.0.0 0.0.0.0 0 0
static (inside,outside) 1.2.3.1 192.168.x.1 netmask 255.255.255.255 0 0
static (inside,outside) 1.2.3.2 192.168.x.2 netmask 255.255.255.255 0 0
access-group acl_out in interface outside
access-group acl_in in interface inside
route inside 0.0.0.0 0.0.0.0 192.168.x.y 0
route outside 0.0.0.0 0.0.0.0 1.2.6.7 1

The ACLs aren't a problem at this point, but I'm not sure if I have icmp configured corrrectly so here goes:
access-list acl_in permit icmp any any echo
access-list acl_out permit icmp any any echo-reply

pix1# show route
      inside 0.0.0.0 0.0.0.0 192.168.x.y 0 OTHER static
      outside 0.0.0.0 0.0.0.0 1.2.6.7 1 OTHER static
      inside 192.168.x.0 255.255.255.0 192.168.x.y 1 CONNECT static
      outside 1.2.6.z 255.255.255.248 1.2.6.8 1 CONNECT static

I'm trying to connect to my ISP/the Internet through the PIX and cannot...the PIX was working fine earlier when it hosted the PPPoE connection, but that's not practical any more, since I need part of my network to connect directly to the ISP, and part of it must remain behind the PIX firewall.  How do I fix this?


ASKER CERTIFIED SOLUTION
Tim Holman
CEO

Our community of experts have been thoroughly vetted for their expertise and industry experience.

Join our community to see this answer!
Unlock 3 Answers and 25 Comments.
Start Free Trial
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 3 Answers and 25 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros