Re: Is it possible to do something like policy routing with a PIXfirewall?

From: Rodgers Moore (rodgers@xxxxxxxxxxxxxx)
Date: Sun Aug 05 2001 - 01:02:44 GMT-3


   
No. The PIX will cannot do what you want. But, that doesn't mean you
can't do it.

What would happen if you implemented PAT backwards on the two routers?
You would translate the Internet into looking like two local hosts.
You'd have no need for any defaults routes as everything is local and
you'd cause traffic to flow back where it came from.

enjoy,

Rodgers Moore

OCTAVIO RODRIGUEZ MARTIN wrote:

> I need to do a PIX route to a different default router
> depending on the source IP address. I have a PIX 515
> (5.2.4) (4 Interfaces) with an outside interface default route.
> For traffic from the outside interface, the PIX (because of
> the default route) try to send unknow IP destination traffic to
> the outside interface but this traffic can't be sent because of
> no xlate's. Then It could be necessary to configure
> static(outside,outside) for every outside destination (Internet).
> Then it could be good to have a different
> default route for traffic from the inside and for the traffic from
> the outside. It could be good too, the PIX to send traffic
> from the ouside interface to the outside interface
> (without the static(outside,outside) command) and use
> only one default route.
> I don't know if anyone can help me
> Thanks
> Octavio.
> **Please read:http://www.groupstudy.com/list/posting.html
**Please read:http://www.groupstudy.com/list/posting.html



This archive was generated by hypermail 2.1.4 : Thu Jun 13 2002 - 10:31:45 GMT-3