Solved

Can a Cisco PIX 501 pass traffic to multiple VLANs?

Posted on 2008-06-20
3
826 Views
Last Modified: 2008-06-29
Here is my set up

DSL--->Cisco Pix 501(IP is in LAN subnet)--->Switch (LAN Subnet wit clients attached)--->Cisco Router---->Switch with 8VLANs (all different subnets than the LAN subnet)

Static routing is configured and working for all VLAN subnets on the PIX and cisco router, a default route is configured on the PIX and Cisco router.

I can get on the internet from the VLANs out through the PIX and ping the PIX LAN IP.

I cannot access any clients on LAN from the VLANs and all clients on the LAN cannot access any clients on the VLANS.

I can ping all clients on the VLANs from inside the PIX and I can ping all clients in the LAN from the Cisco router.

I am not sure where the problem lies, i am thinking I need some type of access list but I have tried quite a few with no luck.

Has anyone come across this type of problem.

Thanks
0
Comment
Question by:pureauto
  • 2
3 Comments
 
LVL 7

Expert Comment

by:naughton
ID: 21836440
the idea behind vlans is exactly what you describe.

the LAN clients would likely be in the native VLAN - and hence should be unable to see and pass traffic to hosts on other Vlans.

0
 

Accepted Solution

by:
pureauto earned 0 total points
ID: 21836689
VLANs are unable to pass traffic between each other or other networks true, unless there is a router invloved to make routing decisions based on a routing table.

I figured out the problem and a solution. The PIX was handing out DHCP to the LAN with its LAN IP configured as the default gateway. For some reason it could not route to the VLANs.  I changed the default gateway to the router instead of the PIX and everything can talk with no problem now. I am changing the design up a bit. DSL-->PIX-->Router-->LAN and VLANs, this leaves me with other switch ports on the PIX open for more routers and future expansion. It also allows all my networks to communicate when needed and break up broadcast domains.




0
 

Author Comment

by:pureauto
ID: 21836698
One other note on this. I changed the DHCP server to be the router instead of the PIX.  The PIX would not allow me to change what it gave out as the DHCP default gateway. I set the PIX up to use the router as its DHCP relay.
0

Featured Post

What Should I Do With This Threat Intelligence?

Are you wondering if you actually need threat intelligence? The answer is yes. We explain the basics for creating useful threat intelligence.

Join & Write a Comment

From Cisco ASA version 8.3, the Network Address Translation (NAT) configuration has been completely redesigned and it may be helpful to have the syntax configuration for both at a glance. You may as well want to read official Cisco published AS…
This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

747 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now