[prev in list] [next in list] [prev in thread] [next in thread] 

List:       cisco-nsp
Subject:    RE: [nsp] REG: PIX Failover Bundle.
From:       "Vinod Anthony Joseph Cherunni" <vac () dsqworld ! com>
Date:       2001-04-23 11:57:09
[Download RAW message or body]

This is a multipart message in MIME format.
--=_alternative 00367EFD65256A37_=
Content-Type: text/plain; charset="us-ascii"

Dear All,

My sincere thanks for all the valuble advice.  As indicated by Mr. Ian in 
the given below - 

In this scenario you have and outside interface on PIX #1 with an address 
of x.x.x.1 and a failover address for the outside interface of x.x.x.2 - 
This .2 address becomes the address for the outside interface on PIX #2. 
You will need to assign different IP's as mentioned above. 

If I define the inside interface on PIX #1 with an address of y.y.y.1 and 
a failover address for the outside interface of y.y.y.2. How will I 
configure say a Win-NT ftp client PC connecting to an Internet host with a 
default gateway. In normal circumstances I would prefer to have such 
client PC's & servers of mine on the inside network point to a single 
default gateway. Typically Cisco routers with two ethernet ports 
configured to build port level redundancy are configured with techniques 
such as IRB, & Backup-interface. Is there something similar here, wherein 
I don't need to define more than one gateway address on all my client 
systems. Or else does the failover PIX do a some kind of Proxy ARP the 
moment a port on the Active unit fails.

In regard to disabling NAT on the PIX, Will the following work. Kindly 
correct me if I am wrong.

nat (inside) 0 0.0.0.0 0.0.0.0  - To disable NAT.

Kindly enlighten me.

With warm regards,
Vinod.
--=_alternative 00367EFD65256A37_=
Content-Type: text/html; charset="us-ascii"


<br><font size=2 face="Arial">Dear All,</font>
<br>
<br><font size=2 face="Arial">My sincere thanks for all the valuble advice. &nbsp;As \
indicated by Mr. Ian in the given below - </font> <br>
<br><font size=2 face="Arial">In this scenario you have and outside interface on PIX \
#1 with an address of x.x.x.1 and a failover address for the outside interface of \
x.x.x.2 - This .2 address becomes the address for the outside interface on PIX #2. \
&nbsp;You will need to assign different IP's as mentioned above. &nbsp;<br> </font>
<br><font size=2 face="Arial">If I define the inside interface on PIX #1 with an \
address of y.y.y.1 and a failover address for the outside interface of y.y.y.2. How \
will I configure say a Win-NT ftp client PC connecting to an Internet host with a \
default gateway. In normal circumstances I would prefer to have such client PC's \
&amp; servers of mine on the inside network point to a single default gateway. \
Typically Cisco routers with two ethernet ports configured to build port level \
redundancy are configured with techniques such as IRB, &amp; Backup-interface. Is \
there something similar here, wherein I don't need to define more than one gateway \
address on all my client systems. Or else does the failover PIX do a some kind of \
Proxy ARP the moment a port on the Active unit fails.</font> <br>
<br><font size=2 face="Arial">In regard to disabling NAT on the PIX, Will the \
following work. Kindly correct me if I am wrong.</font> <br>
<br><font size=2 face="Arial">nat (inside) 0 0.0.0.0 0.0.0.0 &nbsp;- To disable \
NAT.</font> <br>
<br><font size=2 face="Arial">Kindly enlighten me.</font>
<br>
<br><font size=2 face="Arial">With warm regards,</font>
<br><font size=2 face="Arial">Vinod.</font>
--=_alternative 00367EFD65256A37_=--


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic