Security Basics mailing list archives

route on PIX


From: Xaos <xaos () compulink gr>
Date: Wed, 18 Dec 2002 00:42:30 +0200

Hi...
I'm not sure if it's the right list to send the question but it's the only one i've got so here goes nothing... :-) The situation is like this... Somebody at my work decided that it's my job to make some changes to one of our clients' systems but the problem is that i'm supposed to make the change to a PIX firewall and i've never even seen one before today let alone configure one...

This is how the network is set up now (IPs are changed to protect the innocent :-)... Every device has subnet mask 255.255.255.0 so i'll leave that out...
The PIX is set as default gateway on the DC
There are two routes configured in the PIX
route outside 0.0.0.0 0.0.0.0 192.168.0.2 1 and route inside 10.0.1.0 255.255.255.0 10.0.0.199 1

[Zyxel 10.0.1.1]---ISDN Line---[Zyxel 10.0.0.199]---Ethernet---[PIX 10.0.0.15]---Ethernet---[Domain Controller 10.0.0.20]
                                                              |
     [Internet]---ISDN Line---[3COM 192.168.0.2]---Ethernet---|

I have to add another ISDN router (Cisco 803) that will communicate with the lan in the same way the two zyxels do... I've already created another route inside 10.0.2.0 255.255.255.0 10.0.0.200 1 for the new network and i've managed to ping the remote server from within the pix but i just can't get the domain controller to ping the remote server (say 10.0.2.2) unless i set up a static route on the DC itself... But i don't think that's right cause that worked even wihout making any changes on the pix which means that the connection was bypassing the firewall...
Any ideas?

Thanx for your time.... :-)




Current thread: