Solved

Can a Cisco PIX 501 pass traffic to multiple VLANs?

Posted on 2008-06-20
3
835 Views
Last Modified: 2008-06-29
Here is my set up

DSL--->Cisco Pix 501(IP is in LAN subnet)--->Switch (LAN Subnet wit clients attached)--->Cisco Router---->Switch with 8VLANs (all different subnets than the LAN subnet)

Static routing is configured and working for all VLAN subnets on the PIX and cisco router, a default route is configured on the PIX and Cisco router.

I can get on the internet from the VLANs out through the PIX and ping the PIX LAN IP.

I cannot access any clients on LAN from the VLANs and all clients on the LAN cannot access any clients on the VLANS.

I can ping all clients on the VLANs from inside the PIX and I can ping all clients in the LAN from the Cisco router.

I am not sure where the problem lies, i am thinking I need some type of access list but I have tried quite a few with no luck.

Has anyone come across this type of problem.

Thanks
0
Comment
Question by:pureauto
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 7

Expert Comment

by:naughton
ID: 21836440
the idea behind vlans is exactly what you describe.

the LAN clients would likely be in the native VLAN - and hence should be unable to see and pass traffic to hosts on other Vlans.

0
 

Accepted Solution

by:
pureauto earned 0 total points
ID: 21836689
VLANs are unable to pass traffic between each other or other networks true, unless there is a router invloved to make routing decisions based on a routing table.

I figured out the problem and a solution. The PIX was handing out DHCP to the LAN with its LAN IP configured as the default gateway. For some reason it could not route to the VLANs.  I changed the default gateway to the router instead of the PIX and everything can talk with no problem now. I am changing the design up a bit. DSL-->PIX-->Router-->LAN and VLANs, this leaves me with other switch ports on the PIX open for more routers and future expansion. It also allows all my networks to communicate when needed and break up broadcast domains.




0
 

Author Comment

by:pureauto
ID: 21836698
One other note on this. I changed the DHCP server to be the router instead of the PIX.  The PIX would not allow me to change what it gave out as the DHCP default gateway. I set the PIX up to use the router as its DHCP relay.
0

Featured Post

2017 Webroot Threat Report

MSPs: Get the facts you need to protect your clients.
The 2017 Webroot Threat Report provides a uniquely insightful global view into the analysis and discoveries made by the Webroot® Threat Intelligence Platform to provide insights on key trends and risks as seen by our users.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In the hope of saving someone else's sanity... About a year ago we bought a Cisco 1921 router with two ADSL/VDSL EHWIC cards to load balance local network traffic over the two broadband lines we have, but we couldn't get the routing to work consi…
Many of the companies I’ve worked with have embraced cloud solutions due to their desire to “get out of the datacenter business.” The ability to achieve better security and availability, and the speed with which they are able to deploy, is far grea…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

724 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question