Re: Simple PIX 501 config



Thank you so much. I will see what I can get working. My present
config is new, reset to factory defaults.

My PC's need to be configured as 172.31.13.1 subnet 255.255.255.0 and
172.31.1.136 255.255.255.0, correct?

Outsude interface: 172.31.13.2 255.255.255.0
Inside interface 172.31.1.1 255.255.255.0
Correct?



On Sun, 28 May 2006 13:13:51 +0200, "Martin Bilgrav"
<bilgravCUTTHISOUT@xxxxxxxxxx> wrote:


"Matt Scoff" <xxscoffxx@xxxxxxx> wrote in message
news:hcqe729os3guafnqc5ektp1eg9nnvtihg4@xxxxxxxxxx

Basic config: I have two PC's. One is connected to the outside port
(eth0) and the other is connected to the inside port (eth1). I would
like to be able to access any port from the inside PC to the outside
PC. Most importantly ICMP/ping to verify the connectivity.


kinda hard when we dont know you present config.
but what you need is pretty simple.
a global
a nat
a ACL permit icmp
a ACL-group on the outside int.


Outside PC (172.31.13.1)
:
:
Cisco Pix 501
:
:
Inside PC (172.31.1.136)



wow - mind you subnetmasks here !


You can choose the eth0/eth1 ip address's because I am not certain
what they should be. Also let me know if the subnet mask "255.255.0.0"
needs to change on the PC's themselves.

YES !
You can not have both interface in the same subnet.
change subnetmasks to /24 = 255.255.255.0, also on the PIX config for inside
and outside interfaces.


Thanks for your help. I'm still learning in my test environment.

you may what to read the cisco config guides for the PIX.

HTH
Martin Bilgrav


.



Relevant Pages

  • RE: Multiple Interfaces
    ... > The word I have is that FreeBSD cannot run two NICs on ... > the same subnet, which is what your included config shows. ... The trick is to configure second interface with netmask 255.255.255.255. ...
    (freebsd-net)
  • Re: Circular Referencing in C#
    ... I used this problem as an interview question about a month ... I configure it using config files. ... put the interface into the base code libraries. ... > public class A1C1 ...
    (microsoft.public.dotnet.languages.csharp)
  • PPPoE/DSL -- no connectivity
    ... If anyone can give me some config pointers, ... fine and all interfaces are UP, ... Virtual-Access1 unbinds from Interface Dialer1 giving me this debug ... service timestamps debug datetime msec ...
    (comp.dcom.sys.cisco)
  • Re: Cisco T1 Internet Config
    ... If the line is functioning properly with this config, ... I personally would not have used a sub interface in this case as you only ... ip unnumbered command would have moved to the serial interface. ... encapsulation frame-relay IETF -- Do I need this line? ...
    (comp.dcom.sys.cisco)
  • Re: changing pix internal address
    ... I have rewritten the config file to reflect what I feel the configuration should look like. ... I cant just ditch the .1 subnet, I got printers workstations, other routers and servers stuck in there. ... :I want to reconfigure the pix to be on 192.168.41.x but not cause ... :can I bind two addresses to the pix internal interface as an intrim ...
    (comp.dcom.sys.cisco)