judgestone
IS-IT--Management
I looked at every setting in config and looked in PDM; but did not see where to put entries or what entries to add.
I have one pix address 10.10.60.1, with vlans of 10.10.66.X, 10.10.67.X, 10.10.68.X and 10.10.69.X configured on a layer 3 switch behind the pix with all routes etc. configured on the pix. The other pix address is 10.10.62.1 with vlans of 10.10.63.X, 10.10.64.X and 101.10.65.X configured on a layer 3 switch behind the pix with all routes etc. configured on the pix.
All vlans can talk to each other and ping and I can ping all vlans from any other vlans, but I can only ping 10.10.60.1(inside interface)from only 60.X, 66.X, 67.X and 68.X and I can only ping 10.10.62.1(inside interface)from 63.X, 64.X, 65.X.
The two pix are connected via PPTP VPN and again all routes and rules configured.
What I want to do is be able to ping 10.10.60.1 from 10.10.63.5 or any ip on 10.10.63.X, or any other vlans behind the 10.10.60.1 pix and be able to ping 10.10.62.1 from 10.10.68.5 or any ip on 10.10.68.X or any other vlans behind the 10.10.62.1 pix.
Do I need to do a fix up command because it seems I have every other configuration correct but I can not seem to get this to work?
I have one pix address 10.10.60.1, with vlans of 10.10.66.X, 10.10.67.X, 10.10.68.X and 10.10.69.X configured on a layer 3 switch behind the pix with all routes etc. configured on the pix. The other pix address is 10.10.62.1 with vlans of 10.10.63.X, 10.10.64.X and 101.10.65.X configured on a layer 3 switch behind the pix with all routes etc. configured on the pix.
All vlans can talk to each other and ping and I can ping all vlans from any other vlans, but I can only ping 10.10.60.1(inside interface)from only 60.X, 66.X, 67.X and 68.X and I can only ping 10.10.62.1(inside interface)from 63.X, 64.X, 65.X.
The two pix are connected via PPTP VPN and again all routes and rules configured.
What I want to do is be able to ping 10.10.60.1 from 10.10.63.5 or any ip on 10.10.63.X, or any other vlans behind the 10.10.60.1 pix and be able to ping 10.10.62.1 from 10.10.68.5 or any ip on 10.10.68.X or any other vlans behind the 10.10.62.1 pix.
Do I need to do a fix up command because it seems I have every other configuration correct but I can not seem to get this to work?