ExamNotes.net  -  IT certification portal

ForumsCertResearchTop sitesNewslettersFree email
HomeRegister
Exams Notes
Practice exams
Exam games
Questions by email
Online training
Training videos
College degrees
Boot camps
Book store
Links directory
Tell a friend
For webmasters

CompTIA Exam Vouchers
Save money on CompTIA exams
Question of the day
Sign up to receive
interactive practice questions
for MCSE, CompTIA
Cisco and other exams
TestKing
Get MCSE, MCSD, CCNA, CCNP,A+, N+ and many more

* ExamSheets *
Guide for Success!
Actual Questions & Answers
MCSE, MCSD, A+ ,CCNA, CCNP
Oracle 8i, Oracle 9i

Online practice tests

Certification sites

Online university

Online college

Online education

Distance learning

Software forum

Server administration forum

Programming resources






This is interesting: Free IT Magazines | Databases help forum



Cisco > CCNP > PIX configuring 2 'OUTSIDE' interfaces

Show a Printable Version
Email This Page to Someone!
Receive updates to this thread




Featured site: Online CCNP practice exams from Cert21.com



Author PIX configuring 2 'OUTSIDE' interfaces
Peakey
Junior Member




Registered: Feb 2001
Location: Sydney
Country: Australia
State: NSW
Certifications: MCSE, CCNA
Working on: CCNP

Total Posts: 12
PIX configuring 2 'OUTSIDE' interfaces

Hi All,

I’m hoping that someone might be able to suggest a work around for the following.

In a nutshell, I have 2 ISP connections connected to 2 separate ‘outside’ interfaces on my firewall. Both of these interfaces need to communicate with the same server on the ‘inside’ network.

E.G.

Ip address outside 1.1.1.1 255.255.255.0 (goes too ISP 1)
Ip address outside2 2.2.2.2 255.255.255.0 (goes too ISP 2)
Ip address inside 10.10.10.10 255.255.255.0

Static (inside,outside) 1.1.1.250 10.10.10.50 netmask 255.255.255.255
Static (inside,outside2) 2.2.2.250 10.10.10.50 netmask 255.255.255.255
Conduit permit tcp host 1.1.1.250 eq www any
Conduit permit tcp host 2.2.2.250 eq www any

How do I configure a route saying any traffic coming into 1.1.1.250 via 1.1.1.1 goes back out that same interface and any traffic coming into 2.2.2.250 via 2.2.2.2 goes back out that same interface?

My situation at the moment is that if I configure a default route of ‘route outside 0.0.0.0 0.0.0.0 1.1.1.x’ then traffic coming in via 2.2.2.2 goes out 1.1.1.1, this situation is causing issues.

I need to use a destination route of 0.0.0.0 0.0.0.0 as I will be routing back out to the internet.

Any thoughts??

Thanks
Peakey

Report this post to a moderator

Old Post 04-10-02 06:34 AM
Peakey is offline Click Here to See the Profile for Peakey Click here to Send Peakey a Private Message Visit Peakey's homepage! Add Peakey to your buddy list Find more posts by Peakey Reply w/Quote Edit/Delete Message IP: Logged
MadChef
A Huge Fake




Registered: Sep 2000
Location:
Country: USA
State:
Certifications:
Working on: A Sex Farm

Total Posts: 1426

I don't know of anyway to get the pix to do what you want. You can't have a second default route and that's all the Pix is considering when forwarding traffic.
I think you might consider setting things up differently and hang everything off of one outside interface. Most people accept BGP feeds to balance the two links.

MadChef

Report this post to a moderator

Old Post 04-10-02 11:17 AM
MadChef is offline Click Here to See the Profile for MadChef Click here to Send MadChef a Private Message Add MadChef to your buddy list Find more posts by MadChef Reply w/Quote Edit/Delete Message IP: Logged
Yeti-GBR1
A Complete Twit




Registered: Oct 2000
Location: Yeti Town, Yetiville, UK
Country: UK
State:
Certifications: Too many to list.
Working on: Getting a real life outside IT.

Total Posts: 1105
Lightbulb

What about a virtual link (using HSRP) ie the 2 PIX are seen as a Virtual PIX for fault Tolerance (BTW I've never seen a PIX, but I know this works with normal Routers (NOT 2500's though) as I have now tested it in my lab on the 2600's)..just a thought...could be way way off the mark though?


http://www.cisco.com/warp/public/619/index.shtml

__________________
Yeti the Inquisitive

MCNE, MCSE(NT4), MCSE 2000, SCO ACE, LCP, Compaq ASE, CCNA, CCIE Wannabe (part of the Wannabe Boffin Club).

www.yeti-gbr1.co.uk
www.ciscolabs.co.uk

Last edited by Yeti-GBR1 on 04-10-02 at 11:36 AM

Report this post to a moderator

Old Post 04-10-02 11:27 AM
Yeti-GBR1 is offline Click Here to See the Profile for Yeti-GBR1 Click here to Send Yeti-GBR1 a Private Message Visit Yeti-GBR1's homepage! Add Yeti-GBR1 to your buddy list Find more posts by Yeti-GBR1    Yeti-GBR1's ICQ status    Reply w/Quote Edit/Delete Message IP: Logged
haseeb_eng
Senior Member
M




Registered: Oct 2001
Location: Kuwait City
Country: Kuwait
State:
Certifications: CCNA, CCDA, CCNP, CCDP, CCSP, Content Networking, Wireless LAN Design Spec.
Working on: PMP CCIE (R&S) MBA

Total Posts: 1165
Arrow

2 outside interfaces ?

Report this post to a moderator

Old Post 04-10-02 11:52 AM
haseeb_eng is offline Click Here to See the Profile for haseeb_eng Click here to Send haseeb_eng a Private Message Visit haseeb_eng's homepage! Add haseeb_eng to your buddy list Find more posts by haseeb_eng Reply w/Quote Edit/Delete Message IP: Logged
Yeti-GBR1
A Complete Twit




Registered: Oct 2000
Location: Yeti Town, Yetiville, UK
Country: UK
State:
Certifications: Too many to list.
Working on: Getting a real life outside IT.

Total Posts: 1105

Hmmm just been informed by a Mate that HSRP on PIX is "Fail Over" dam...well I tried

__________________
Yeti the Inquisitive

MCNE, MCSE(NT4), MCSE 2000, SCO ACE, LCP, Compaq ASE, CCNA, CCIE Wannabe (part of the Wannabe Boffin Club).

www.yeti-gbr1.co.uk
www.ciscolabs.co.uk

Report this post to a moderator

Old Post 04-10-02 11:52 AM
Yeti-GBR1 is offline Click Here to See the Profile for Yeti-GBR1 Click here to Send Yeti-GBR1 a Private Message Visit Yeti-GBR1's homepage! Add Yeti-GBR1 to your buddy list Find more posts by Yeti-GBR1    Yeti-GBR1's ICQ status    Reply w/Quote Edit/Delete Message IP: Logged
Yeti-GBR1
A Complete Twit




Registered: Oct 2000
Location: Yeti Town, Yetiville, UK
Country: UK
State:
Certifications: Too many to list.
Working on: Getting a real life outside IT.

Total Posts: 1105

Yip something like this :

__________________
Yeti the Inquisitive

MCNE, MCSE(NT4), MCSE 2000, SCO ACE, LCP, Compaq ASE, CCNA, CCIE Wannabe (part of the Wannabe Boffin Club).

www.yeti-gbr1.co.uk
www.ciscolabs.co.uk

Report this post to a moderator

Old Post 04-10-02 12:11 PM
Yeti-GBR1 is offline Click Here to See the Profile for Yeti-GBR1 Click here to Send Yeti-GBR1 a Private Message Visit Yeti-GBR1's homepage! Add Yeti-GBR1 to your buddy list Find more posts by Yeti-GBR1    Yeti-GBR1's ICQ status    Reply w/Quote Edit/Delete Message IP: Logged
cisco_kidd20
Member




Registered: Apr 2002
Location:
Country: United States
State:
Certifications: A+, CCNA
Working on: CCNP, MCP, CSS

Total Posts: 45

Try www.routergod.com They are very good and humorous!!

Report this post to a moderator

Old Post 04-10-02 12:56 PM
cisco_kidd20 is offline Click Here to See the Profile for cisco_kidd20 Click here to Send cisco_kidd20 a Private Message Add cisco_kidd20 to your buddy list Find more posts by cisco_kidd20 Reply w/Quote Edit/Delete Message IP: Logged
Peakey
Junior Member




Registered: Feb 2001
Location: Sydney
Country: Australia
State: NSW
Certifications: MCSE, CCNA
Working on: CCNP

Total Posts: 12

Thanks for the replys guys.... I will try an organise an alternate solution.

Peakey

Report this post to a moderator

Old Post 04-10-02 10:29 PM
Peakey is offline Click Here to See the Profile for Peakey Click here to Send Peakey a Private Message Visit Peakey's homepage! Add Peakey to your buddy list Find more posts by Peakey Reply w/Quote Edit/Delete Message IP: Logged
All times are GMT.
Post new thread   Post reply

Click here for CCNP study guides

Cisco exam notes



Forum Jump:
Rate This Thread:
Forum Rules:
Who Can Read The Forum? Any registered user or guest.
Who Can Post New Topics? Any registered user.
Who Can Post Replies? Any registered user.
Changes: Messages can be edited by their author.
Posts: HTML code is OFF. Smilies are ON. vB code is ON. [IMG] code is ON.
 

ExamNotes forum archive


Powered by: vBulletin 2.2.8
Copyright ©2000, Jelsoft Enterprises Limited.

  Free Braindumps | mcse braindumps