Cisco PIX 515 Reconfiguration for new T-1 Line

Hi All,

I am having trouble with reconfiguring our PIX 515 for our new data line. We're currently on a Frame Relay and are changing over to a T-1 from another provider. After making the necessary changes to the router configuration, I am able to able to surf the Internet by connecting a laptop directly up to the router using a cross-over cable, so I know the new T-1 line is provisioned correctly for Internet traffic.

Lasptop Settings:
Laptop IP Address:
Default Gateway: (Routers IP Address)

Using the same router configuration and making the necessary changes in the PIX, I cant access the Internet. After making the changes to the PIX and writing them to memory, I reboot the PIX and the router, but Internet traffic does not flow.

Below are the changes that I made to the router. After implementing the changes, I was able to hook a laptop up directly to the router (using a cross-over cable) and use the Internet, so I know the data line is provisioned and working correctly. The technician from Logix also did the same.

ip domain-lookup
ip name-server
ip name-server
interface FastEthernet0/0
 description public addresses for ethernet LAN
  ip address
 duplex auto
 speed auto
interface Serial0/0
 description T1 Connection to Logix
 ip address
 encapsulation HDLC
 no ip directed-broadcast
 service-module t1 timeslots 1-24
interface Serial0/1
  no ip address
ip classless
ip route

Any ideas what I am doing wrong? We do also have a "Point-toPoint" data line installed that goes directly to our office in Taiwan. It's internal address is I am going to attempt the changes again Friday evening after work.

Thank you very much.
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

The first thing that I see when I look at your "pix-after-changes-0108.doc" configuration, is that you are NAT'ing your internal traffic to a public IP that is not in your new public block of IP addresses.  See the command below:

global (outside) 1

Your public range is, which includes useable addresses between .193-.198 and does not include .206 as in the global command above.  Change your global to use one of the public addresses in your range and try again.  Use these commands:

no global (outside) 1
global (outside) 1         <---whichever one between .195-.198 you desire, since .193-.194 are used
clear xlate

You also have some static translations and conduit statements that you will have to modify as well, for the same reason as stated above.

Hope that helps...
bearnkatAuthor Commented:
Thank you I apprecaite the help very much, I'll give the configuration changes a try tomorrow evening after work and let you know the outcome.

bearnkatAuthor Commented:

After what you pointed out I started looking at the IP configuration sheet that Logix provided. I didn't even think about checking the public IP address range against the subnet. They have the subnet down as They made a typo and it should have been That will make all the difference in the world I'll be taking care of the configuration change this evening and will let you know the outcome.

Thank you again,

The Ultimate Tool Kit for Technolgy Solution Provi

Broken down into practical pointers and step-by-step instructions, the IT Service Excellence Tool Kit delivers expert advice for technology solution providers. Get your free copy for valuable how-to assets including sample agreements, checklists, flowcharts, and more!

Good deal...that should help a lot!

Good luck!

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
bearnkatAuthor Commented:
Success! Thank you so much. All is working perfectly now. I feel I should charge the provider for my time since they made the typo!

Thank you again for your expert assistance!

bearnkatAuthor Commented:
Absolutely outstanding help! Thank you, thank you!
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today

From novice to tech pro — start learning today.