Compare cert salaries and plan your next career move
docrice wrote: » This may seem like a rather obvious question, but does your outside interface have an address that's within the net space / subnet of the forwarding gateway (207.247.114.43)? I didn't see any mask information so I figure we should check that.
docrice wrote: » You're referring to a route for 207.217.114.40/29 but your ISP's gateway is at 207.247.114.43? Is this a typo?
Technology1 wrote: » 207.217.114.40 is the static ip address
outside 0.0.0.0 0.0.0.0 70.19.119.1 1 OTHER static inside 172.16.223.0 255.255.255.0 172.16.223.1 1 CONNECT static outside 207.217.114.40 255.255.255.248 207.217.114.42 1 CONNECT static
interface Ethernet0 description blahblah speed 100 duplex full nameif outside security-level 0 ip address 1.2.3.4 255.255.255.0 standby 1.2.3.254
docrice wrote: » If your PIX's outside interface is 207.217.114.40, and your next hop at the ISP is supposed to be 207.247.114.43, this can't route since they're not part of the same subnet given a /29 net. The second octet values makes these two completely out of range of each other. Or am I missing something here? Do you have another router in front of the PIX that you control which ultimately connects to the ISP?
docrice wrote: » I've been in a rush today so I've been skimming at the responses and my eyes haven't been catching everything. Are you sure this is the address assigned to your outside interface? This looks like a static route config, which means 207.217.114.40 would be the network subnet identifier. An interface config output should look like: Your PIX code might be old enough where the config output might look somewhat different as I haven't worked on the 6.x versions in ages, but I don't think it should be that different. I agree with mgeorge - you really should update to 8.0(4), even though that in itself is a few years old now. Be careful though - there are some syntax changes after you upgrade from 6.x. In any case, shouldn't your route command be: route outside 0.0.0.0 0.0.0.0 207.217.114.43 1, assuming the ISP is the next hop from the PIX? Or did you originally do route outside 0.0.0.0 0.0.0.0 237.xxx.xxx.xxx 1 because the next hop upstream actually has a starting octet of 237? As mentioned before, I might be making wrong assumptions about your topology. It just sounded like your ISP is the next hop from your PIX.
Compare salaries for top cybersecurity certifications. Free download for TechExams community.