[Last Call] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

Multiple IPs on Internal interface?

Posted on 2007-12-04
10
Medium Priority
?
302 Views
Last Modified: 2010-04-21
I have two networks behind my pix.  192.168.0.0/24, so 192.168.0.1 is the IP of my internal interface.  I added a second subnet, 192.168.1.0/24.  In order for machines with IPs in that network to get out through the pix it needs to have an IP in that subnet, 192.168.1.1, so that I can set that to be their default gateway.

The only way I see to do this is with a sub-interface, which requires a different vlan.  Am I missing something?

This is similar to a previous post, but I'm not getting an answer on it, so this is a re-phrase.  If you can help me out I'll give you points for both.
0
Comment
Question by:arrkerr1024
  • 5
  • 3
  • 2
10 Comments
 
LVL 8

Accepted Solution

by:
Jeff Perry earned 1400 total points
ID: 20408349
Where did you add your second subnet? I am not sure if the PIX supports a sub-interface but if it has an open interface you could make that second network a dmz and assign nat from that network to your outside ip addresses.

On the other hand if you have capeable core network equipment that will handle the routing of the new internal network then all you would have to do is again create a nat for the new network to gain external access.

What is the first device on the inside on the 192.168.0.x/24 network?
0
 
LVL 3

Expert Comment

by:RouterDude
ID: 20408364
Change your subnet masking and supernet your internal network. go with 255.255.254.0 for the 192.168.0.0 and keep the pix at .1. This is easiest to do if you use DHCP that way you dont have that many devices to change. Alternate method would be to upgrade the PIX with a second NIC card and licensing if you dont have it. This is assuming it is a 515E.
0
 
LVL 14

Author Comment

by:arrkerr1024
ID: 20408384
In reality I'm dealing with public IP blocks assigned by my ISP, but things are done in a strange way on their end.

192.168.0.1 is my pix.  192.168.0.x are a bunch of servers.  That subnet is full (its really a much smaller subnet), so I've been assigned 192.168.1.0/24 as well.  So I've put 192.168.1.10 in a server behind my pix... but I can't make 192.168.0.1 my gateway on that server, since it isn't on the same network.  I need the pix to also have 192.168.1.1, in addition to 192.168.0.1.  Otherwise, how are machines on 192.168.1.0/25 supposed to get out?
0
Choose an Exciting Career in Cybersecurity

Help prevent cyber-threats and provide solutions to safeguard our global digital economy. Earn your MS in Cybersecurity. WGU’s MSCSIA degree program was designed in collaboration with national intelligence organizations and IT industry leaders.

 
LVL 14

Author Comment

by:arrkerr1024
ID: 20408393
I can't change subnetting since these aren't really the networks - in reality they are two small ones very far apart.

DHCP on PIX is more than retarted (no reservations!), and no I'm not using DHCP.

This is an ASA 5510 running 8.0(2).  I have more interfaces, but no physical access at this time to run another cable to an interface.
0
 
LVL 3

Assisted Solution

by:RouterDude
RouterDude earned 600 total points
ID: 20411481
if you have an available interface, that would be the one of the ways to do it, but since you say you have a 5510, you can subinterface the one connected provided you are connecting to a Cisco switch. You can create a DOT1q trunk between the ASA and the switch and setup subinterfaces off that interface for each vlan. Those are about the only two options available for what you are describing.
0
 
LVL 14

Author Closing Comment

by:arrkerr1024
ID: 31412763
Yep... I'm just SOL on the easy way.  Another fun limitation of PIX.
0
 
LVL 8

Expert Comment

by:Jeff Perry
ID: 20412217
Ok so the 192.168.0.x and 192.168.1.x networks are not real they are just the numbers you are using to represent the address blocks assigned by your ISP?

If so is there no private addressing scheme in place on your network?
0
 
LVL 14

Author Comment

by:arrkerr1024
ID: 20412255
There is, I was just simplifying the question to avoid confusion.

I have two subnets of public IPs for my use, and a tiny one between my pix and the data center.

One of those subnets of public IPs is NATed to my private network.  One of those subnets I want to be able to assign the public IP directly to the machine, rather than NAT them.  Why?  Because the control panel software we use (plesk) doesn't handle having an internal address very well (it thinks it should use that private IP when it sets up DNS, etc... so I need the machine to know its real IP).

Usually I use NAT and give all of my machines private IPs and just NAT through the ones that need to be on the internet.  The addition of this control panel software has thrown a bit of a wrench in my network setup.
0
 
LVL 3

Expert Comment

by:RouterDude
ID: 20412836
Static (inside,outside) 192.168.1.2 192.168.1.2 netmask 255.255.255.255 works in that situation too. you basically nat the same IP at both interfaces.Only drawback I see for that is your gateway address for the machine, unless you bind a private IP and gateway to the nic in addition to the public IP. If you do that, just make sure to have a good ACL in place.
0
 
LVL 14

Author Comment

by:arrkerr1024
ID: 20413468
Ya, right, I could just have an IP on both subnets on the box.  Not on awful solution... since you CAN add multiple IPs to an interface in anything OTHER than a pix :-P.  It just seems like a huge oversight to not allow a second IP on an interface (that isn't on a vlan).... I could see that back in the day, but 8.0 just came out... why don't they fix these things already!  Sheesh.
0

Featured Post

Transaction-level recovery for Oracle database

Veeam Explore for Oracle delivers low RTOs and RPOs with agentless transaction log backup and transaction-level recovery of Oracle databases. You can restore the database to a precise point in time, even to a specific transaction.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

For months I had no idea how to 'discover' the IP address of the other end of a link (without asking someone who knows), and it drove me batty. Think about it. You can't use Cisco Discovery Protocol (CDP) because it's not implemented on the ASAs.…
In this article, the configuration steps in Zabbix to monitor devices via SNMP will be discussed with some real examples on Cisco Router/Switch, Catalyst Switch, NAS Synology device.
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Suggested Courses

834 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question