PIX dual homed for internal routing



I have a PIX 515E with 3 NICs. I am not a "Cisco guy" so my
experience is somewhat limited. I have worked with other similar
products from other vendors.

I will be using the PIX to provide VPN access and VPN access only. I
will be placing the VPN outside NIC into my DMZ with a public IP
address.

I have a single address space /28 that makes up my logical DMZ. I
have this split across multiple physical DMZ networks by utilizing
host level routing. The range doesn't really exist as a network
anywhere, if you follow.
I have made a request of my ISP for additional address space, which is
taking a long time.

Each device has a public IP (1.2.3.4) as well as a private IP
(192.168.0.1) My other firewall has routing in place to get to
1.2.3.4 mask 255.255.255.255 via 192.168.0.1 and then to get to
1.2.3.5 mask 255.255.255.255 via 192.168.100.1. And so on. I don't
like this, but this is what I have & it works.

The problem is I can't seem to multihome the PIX and give it both an
private IP and a public IP address. AFAIK the PIX doesn't support
this. Is there any way around this, shy another router between the
PIX and the DMZ? I was able to stick another router in place and make
this all work the way I want -- except I don't want another physical
router just for this.

I have 3 NICs on the PIX, I really only need two. I want outside in
my DMZ, Inside on my inside, and I really don't need the 3rd. Can I
utilize that 3rd NIC somehow and have the PIX route from it to the
public IP address on the 'OUTSIDE' which doesn't plug into a real
logical network? So far all attempts fail with "no route to /
dmzsourceip/ from /outside/" as if the PIX was accepting the traffic
on the 3rd NIC, but sending the response from the outside NIC.

.



Relevant Pages

  • Pix and router configuration
    ... Wonder if anyone can help me with the cisco pix configuration. ... ROUTER B ... outside, inside, dmz. ... Host from DMZ can talk to the host from inside of the pix as well. ...
    (comp.dcom.sys.cisco)
  • Re: PIX FireWall and SBS
    ... I would advise using the dual nic setup with SBS2k3 and the PIX. ... network configurations for two nics and a router which will show the IP ... and the workstations would use the server internal nic as a gateway. ... If Earthlink do not use PPoE the configuration above won't be usable. ...
    (microsoft.public.windows.server.sbs)
  • Re: Two Nics really needed?
    ... Seems like the T1 router and the PIX can remain unchanged. ... your external NIC on the SBS in the same subnet as the LAN side of the PIX. ... Then the SBS server internal NIC and the workstation NICs plug into the ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: ISA behind PIX scenario
    ... Create an entirely new private IP subnet to go between the ISA and PIX. ... This subnet will become a DMZ known as a "Back-to-back DMZ" design. ... > But i am confused about the NICs configurations? ...
    (microsoft.public.isa)
  • Re: 4th nic for pix 525
    ... :I'm thinking of installing another NIC on our Cisco PIX 525. ... :another one for a second DMZ. ... There are no 3rd party NICs supported on the PIX. ...
    (comp.dcom.sys.cisco)