Solved

PIX 515E - Two ISP's - Trying to create static routes for individual hosts

Posted on 2008-06-19
2
387 Views
Last Modified: 2008-06-20
I just got a second ISP in today which I planned on using to have a couple web servers use, while leaving the rest of my users/servers using my primary ISP as they have been.  

What I was trying to do was create a static route for individual inside hosts... ie -  
192.168.1.10 255.255.255.255  -->  external_gatewayIP_of_2nd_ISP

When i do this, it tries, but renders that host unable to get anywhere on the internet.  I couldn't even access the inside interface (192.168.1.1) from that host (via telnet) after I added that route.  

How can I configure the pix so that I can have 1 or 2 servers nat out through to the 2nd ISP interface?

0
Comment
Question by:xenetar
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 19

Accepted Solution

by:
nodisco earned 500 total points
ID: 21827182
No can do I'm afraid.  A PIX cannot have 2 gateways out for the simple reason that regardless of which network you are coming from, you still to route a default gateway network of 0.0.0.0 to a destination, and you can only have one default gateway.

If you have 2 ISPs, you *can* use BGP between 2 border routers to load-balance and/or provide redundancy.  A pix though, cannot route default 0.0.0.0 out to any more than 1 destination.

hth
0
 
LVL 1

Author Comment

by:xenetar
ID: 21829675
So I need a second Pix to do the job and change the gateway on those few internal hosts to point to the second pix to make this work?
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Monitor Internet Edge Router behind Firewall 2 37
ASA 5505 packet drops 14 70
Site to Site VPN DNS issue 6 41
Change "enable" password on Cisco Router 7 57
From Cisco ASA version 8.3, the Network Address Translation (NAT) configuration has been completely redesigned and it may be helpful to have the syntax configuration for both at a glance. You may as well want to read official Cisco published AS…
Use of TCL script on Cisco devices:  - create file and merge it with running configuration to apply configuration changes
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question