We have a PIX 520 with a total of 6 Ethernet interfaces. Currently, we're using four of the interfaces (outside, inside, dmz1, dmz2).
Here's where things get intersting. We have two different ISPs supplying us with a total of three lines (one frac T-3, two T-1s). The frac. T-3 is for a specific application, and we don't want to put other clients on that line. We have 5 different public IP blocks (1 for frac. T-3, and 4 for the T-1s). Both routers (one for T-3, one for both T-1s) are on the same physical network.
I can get the PIX to hold a static IP in one of the T-1 blocks for a server, but when the traffic tries to go back out, it tries to send it back the T-3, which causes "Deny tcp reverse path check from aa.bb.cc.dd to ee.ff.gg.hh on interface outside". It should be going out the interface I've named "outside2," which has an IP address in the same T-1 block as the aforementioned static IP.
This question has been asked before, but I can't seem to find appropriate answers. Can you have a PIX 520 that has TWO outside interfaces? And can you route traffic to/from one particular DMZ (say DMZ3) to/from a particular outside interface (say outside2)?
Thanks!
Dan
Here's where things get intersting. We have two different ISPs supplying us with a total of three lines (one frac T-3, two T-1s). The frac. T-3 is for a specific application, and we don't want to put other clients on that line. We have 5 different public IP blocks (1 for frac. T-3, and 4 for the T-1s). Both routers (one for T-3, one for both T-1s) are on the same physical network.
I can get the PIX to hold a static IP in one of the T-1 blocks for a server, but when the traffic tries to go back out, it tries to send it back the T-3, which causes "Deny tcp reverse path check from aa.bb.cc.dd to ee.ff.gg.hh on interface outside". It should be going out the interface I've named "outside2," which has an IP address in the same T-1 block as the aforementioned static IP.
This question has been asked before, but I can't seem to find appropriate answers. Can you have a PIX 520 that has TWO outside interfaces? And can you route traffic to/from one particular DMZ (say DMZ3) to/from a particular outside interface (say outside2)?
Thanks!
Dan