?
Solved

Can a Cisco PIX 501 pass traffic to multiple VLANs?

Posted on 2008-06-20
3
Medium Priority
?
837 Views
Last Modified: 2008-06-29
Here is my set up

DSL--->Cisco Pix 501(IP is in LAN subnet)--->Switch (LAN Subnet wit clients attached)--->Cisco Router---->Switch with 8VLANs (all different subnets than the LAN subnet)

Static routing is configured and working for all VLAN subnets on the PIX and cisco router, a default route is configured on the PIX and Cisco router.

I can get on the internet from the VLANs out through the PIX and ping the PIX LAN IP.

I cannot access any clients on LAN from the VLANs and all clients on the LAN cannot access any clients on the VLANS.

I can ping all clients on the VLANs from inside the PIX and I can ping all clients in the LAN from the Cisco router.

I am not sure where the problem lies, i am thinking I need some type of access list but I have tried quite a few with no luck.

Has anyone come across this type of problem.

Thanks
0
Comment
Question by:pureauto
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 7

Expert Comment

by:naughton
ID: 21836440
the idea behind vlans is exactly what you describe.

the LAN clients would likely be in the native VLAN - and hence should be unable to see and pass traffic to hosts on other Vlans.

0
 

Accepted Solution

by:
pureauto earned 0 total points
ID: 21836689
VLANs are unable to pass traffic between each other or other networks true, unless there is a router invloved to make routing decisions based on a routing table.

I figured out the problem and a solution. The PIX was handing out DHCP to the LAN with its LAN IP configured as the default gateway. For some reason it could not route to the VLANs.  I changed the default gateway to the router instead of the PIX and everything can talk with no problem now. I am changing the design up a bit. DSL-->PIX-->Router-->LAN and VLANs, this leaves me with other switch ports on the PIX open for more routers and future expansion. It also allows all my networks to communicate when needed and break up broadcast domains.




0
 

Author Comment

by:pureauto
ID: 21836698
One other note on this. I changed the DHCP server to be the router instead of the PIX.  The PIX would not allow me to change what it gave out as the DHCP default gateway. I set the PIX up to use the router as its DHCP relay.
0

Featured Post

When ransomware hits your clients, what do you do?

MSPs: Endpoint security isn’t enough to prevent ransomware.
As the impact and severity of crypto ransomware attacks has grown, Webroot has fought back, not just by building a next-gen endpoint solution capable of preventing ransomware attacks but also by being a thought leader.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In the hope of saving someone else's sanity... About a year ago we bought a Cisco 1921 router with two ADSL/VDSL EHWIC cards to load balance local network traffic over the two broadband lines we have, but we couldn't get the routing to work consi…
How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…
Suggested Courses
Course of the Month13 days, 23 hours left to enroll

801 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question