Solved

Cisco router in between Pix and Switch - routing needed?

Posted on 2008-10-21
6
347 Views
Last Modified: 2012-05-05
I Have a Cisco 2621 router that I am going to place in between my Switch and my PIX-501 to collect and export netflow. I really just want it to collect the Netflow and pass on the traffic to the pix. What commands would I need to use to do this (if any)
here is the format of the connection Legend (inside ip-[hardware]-outside ip)
Current
LAN->(C3560-10.10.10.2)->(10.10.10.254-[PIX-501]-0.0.0.0)
Desired Setup
LAN->(C3560-10.10.10.2)->(10.10.10.254-[2621-router]-10.10.9.230)->(10.10.9.254-[PIX-501]-0.0.0.0)

I already have the config of the 2621 setup this way and I'm going to test it tonight after hours but I wanted to find out before if I need any other routes to make the passthrough happen.

Also does there need to be any other changes to the PIX other than changing the inside IP? It is the gateway for the LAN. So with the desired setup the Gateway would be changed to the 2621 and traffic would be passed to the pix I guess.
0
Comment
Question by:Bill Warren
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
6 Comments
 
LVL 43

Expert Comment

by:JFrederick29
ID: 22768550
The 3560 needs a default route via 10.10.10.254 (the 2621) and the 2621 needs a default route via 10.10.9.254 (PIX).  The PIX needs a route to 10.10.10.0/24 via 10.10.9.230 (2621) and the 3560 a route to 10.10.9.0/24 via 10.10.10.254 (2621).  That should do it these are your only subnets.
0
 

Author Comment

by:Bill Warren
ID: 22768686
Sorry I don't have a ton of knowledge on the routes. if it's not too much trouble could you tell me  the commands that I woul d need to add per device? I am into the devices and know how to add them but I'n not sure on the connamds that need to be added.
0
 
LVL 43

Accepted Solution

by:
JFrederick29 earned 500 total points
ID: 22768709
Sure.

3560:

conf t
ip route 0.0.0.0 0.0.0.0 10.10.10.254
ip route 10.10.9.0 255.255.255.0 10.10.10.254

2621:

conf t
ip route 0.0.0.0 0.0.0.0 10.10.9.254

PIX:

conf t
route outside 0.0.0.0 0.0.0.0 x.x.x.x   <--to your ISP (should already be there so no need to add)
route inside 10.10.10.0 255.255.255.0 10.10.9.230
0
[Live Webinar] The Cloud Skills Gap

As Cloud technologies come of age, business leaders grapple with the impact it has on their team's skills and the gap associated with the use of a cloud platform.

Join experts from 451 Research and Concerto Cloud Services on July 27th where we will examine fact and fiction.

 

Author Comment

by:Bill Warren
ID: 22769039
on the pix when I try the command I get

pixfirewall(config)# ip route route inside 10.10.10.0 255.255.255.0 10.10.9.230
Not enough arguments.
Usage:  [no] ip address <if_name> <ip_address> [<mask>]
        [no] ip address <if_name> <ip_address> <mask> pppoe [setroute]
        [no] ip address <if_name> dhcp [setroute] [retry <retry_cnt>]
        [no] ip address <if_name> pppoe [setroute]
        ip local pool <poolname> <ip1>[-<ip2>] [mask <mask>]
        ip verify reverse-path interface <if_name>
        ip audit {info|attack} action [alarm] [drop] [reset]
        ip audit name <audit_name> {info|attack} [action [alarm] [drop] [reset]]

        ip audit interface <if_name> <audit_name>
        ip audit signature <sig_number> disable
        show|clear ip audit count [global] [interface <interface>]
        show ip [address [<if_name> [pppoe|dhcp [lease|server]]]]
Does the "ip route" work on the pix-501?
0
 
LVL 43

Expert Comment

by:JFrederick29
ID: 22769050
Drop the "ip route" portion.  It's just:

route inside 10.10.10.0 255.255.255.0 10.10.9.230
0
 

Author Closing Comment

by:Bill Warren
ID: 31508354
Thanks a ton!
0

Featured Post

Simple, centralized multimedia control

Watch and learn to see how ATEN provided an easy and effective way for three jointly-owned pubs to control the 60 televisions located across their three venues utilizing the ATEN Control System, Modular Matrix Switch and HDBaseT extenders.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Concerto Cloud Services, a provider of fully managed private, public and hybrid cloud solutions, announced today it was named to the 20 Coolest Cloud Infrastructure Vendors Of The 2017 Cloud  (http://www.concertocloud.com/about/in-the-news/2017/02/0…
Many of the companies I’ve worked with have embraced cloud solutions due to their desire to “get out of the datacenter business.” The ability to achieve better security and availability, and the speed with which they are able to deploy, is far grea…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Suggested Courses
Course of the Month7 days, left to enroll

623 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question