Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium


Require Help urgently In Troubleshooting Pix

Posted on 2011-02-27
Medium Priority
Last Modified: 2012-05-11
Hi, I hope someone can help me with a frustrating and time consuming issue I curreently have with getting Internet access on all our machines in the new infrastructure.
I have done a lot of trouble shooting with a network colleague, but hes not familiar with Pix or specialist firewall stuff.

The issue is as follows. My client is a small organisation which has recently upgraded and updated all its infrastucture to replace old kit.

We have set up new W2008 servers, a new AD, new DNS, DHCP, Hyper-V running Exchange 2010, Sharepoint 2010, CRM. All of this works great.
We have put in new switches, before the client had a very flat structure consisting of 1 VLAN and one 192.168.2.x subnet, hosting all computers, printers, etc.
Now they have 4 other vlans, a 3.x to host all new servers as above and to which all the users will migrate their pcs too.
4.x is for Iscsi
5.x is for WAP.

Up until Saturday morning, all was working fine, and so we removed the old kit from the racks, and prepared the room to move the new kit, which is sitting in a corner of the room, but all patched in to the network. We hoped to moed this over the last 2 days, but I have been stuck with a internet access issue and I cant work out whats went wrong or how to troubleshoot and get to the cause and fix.

There is a Pix 515E firewall, which is connected to Zyxel 300 and Zyxel 700 routers and then to the switches.

I have attached a diagram showing how the 4 switches are connected and the configs of these 4 swotches and the PIX.

In the diagram, A is the incoming line from the ISP, which goes to a 700 Zyxel Series router, and this is linked via a small ethernet cable to a port on a 300 Zyxel router. I am not sure why its this way, the ISP says there is only 1 router (the 700).
When I started here a few weeks back the original guy had left so I cant ask about the config. I managed to get the PIX password and get the config but I have to console to it as I cant access it via telnet like the other 4 switches, which I had set up.

Anyway the PIX is soon coming out and will be replaced with a TMG firewall solution. This is due to the PIX age.

I have a seperate EE question in to the forum to address a TLG NLB and teaming issue, so I cant replace the firewall just yet, though I may have to if I cant get the firewall working again.

On Saturday, power was lost to the routers and pix, and since we switched it on, we cant get internet access, yet our ISP and my colleague can remote on to the IP it seems.

Nothing was changed on the PIX recently, though in the last day I have changed its IP from to and back again during the troubleshooting.

I have attyached all the configs.

I am hoping that someone can look at the setup and say where the issue may be. Or be able to provide me with some PIX commands that I can use to troubleshoot the issue, I tried to ping out and do a tracert from the PIX, but I dont know the proper syntax.

The customer has 6 allocated IP addresses and as I say, up till Saturday and the switch off, all was fine.

The PIX is back online and pinging on the address

This could be an issue with the ISP still, or with the set up. The equipment we took out should not have affected this routing or set up.

I really hope someone can help.

I plan to tomorrow build out the TMG firewall and try that and bypass the PIX. And I plan to maybe blow the config off the PIX as it contains old legacy VPN stuff and access lists whcih have never worked or been there for years, I just want simple set up NATing to the 6 addresses as shown in the config. We can add new VPN on the TMG later.

I just want to get internet access back to the new infrastructure asap. All internal DNS, etc working fine.

A few otehr points which may help, as I say the ISP thinks there is only 1 700 router, we dont know why there is a 300 there, but the PIX is attacdhed to that 300. When I took the cable out and put it in the 700 earlier, to bypass the 300, my colleague could not remote connect.
Putting it back allowed him to telnet from remote over tjhe internet, and the ISP believes traffic is passing.
We did get a small trickle of email coming in when I replaced the cable back to its original set up.

Previously mail coming when to and, these machines are now away, and the mail should go to
We tested it on external address 178 as you can see from the config. We hope to replace the otehr 2 incomings NATS to as well

Many thanks


 Topology vwswi01.txt vwswi02.txt vwswi03.txt vwswi04.txt Pix.txt
Question by:Croftkey
  • 3
  • 2
  • 2
LVL 57

Expert Comment

ID: 34993769
It has been awhile since I have any work on a PIX and I will try and help as much as possible.

The first thing I did notices it that you have:

     route inside 1

In the config, which means the pix can't be, other wise it would be pointing to itself as the router for all devices in te subnet.  If it could route to that whole subnet, you would not need the route statement.  There needs to be some other layer 3 device (route) on the inside that has that IP address.
LVL 57

Expert Comment

ID: 34993829
The following IP addresses on the inside should be able to telnet into the pix:

Are there specific IP subnets that can not get to the Internet?

From the Internet can you access the servers on the inside that you need to?
LVL 79

Expert Comment

ID: 34994215
>route inside 1
This route should not point to itself as the next hop
The IT Degree for Career Advancement

Earn your B.S. in Network Operations and Security and become a network and IT security expert. This WGU degree program curriculum was designed with tech-savvy, self-motivated students in mind – allowing you to use your technical expertise, to address real-world business problems.


Author Comment

ID: 34994756
Hi thanks to all for replying.

So should I make the rout inside statement point to which is the ip address of the lqyer3 switch vwswi04?

I tried telneting using those 3 ips using putty but when it connects it gives me a blank session then closes.
LVL 79

Accepted Solution

lrmoore earned 2000 total points
ID: 34996473
Yes, you need to change the route statement to point to the L3 switch!

Author Comment

ID: 34996578
Hi this is resolved, I may have made a change and not committed it, or it may have been a line fault.
A few weeks ago I had saved a copy of the PIX config and I basically changed all to the way it was, and so far so good.

In a few days time I need to move all the kit into the rack but this is just moving servers. The switch where the Pix connects to will also move but as long as I note where everything plugs into it should be okay. We dont need to switch off the routers or pix for this move.

Thanks all for your help

Author Closing Comment

ID: 34996583
Routing will have been the issue

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

WARNING:   If you follow the instructions here, you will wipe out your VTP and VLAN configurations.  Make sure you have backed up your switch!!! I recently had some issues with a few low-end Cisco routers (RV325) and I opened a case with Cisco TA…
You deserve ‘straight talk’ from your cloud provider about your risk, your costs, security, uptime and the processes that are in place to protect your mission-critical applications.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …

569 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question