judgestone
IS-IT--Management
I will try not to rant, but I have a question concerning possible pix506e not understanding VLAN for routing of separate VLAN on inside interface. I will propose a simple scenario and would appreciate an answer since I have been working on this for a week to no avail.
Scenario:
1. Pix 506e - IP External: 209.XXX.XXX.XXX, IP Internal: 10.10.60.X
2. A DLink 3326SMR layer 3 switch with default VLAN - ports 23-24, IP: 10.10.60.254, VLAN2 - ports 1-4, IP: 192.168.2.254
Default Gateway for Default VLAN 10.10.60.X from Pix 506e. RIP is enabled and have set up Group VLANs to dynamically join other VLANs.
Here is my problem. I can from the switch ping the interface addresses of both VLANs (10.10.60.X, 10.10.60.254, 192.168.2.254) and can ping a laptop with an IP Address of 192.168.2.8 in port 1 on VLAN2.
From the laptop 192.168.2.8 I can ping 10.10.60.254, 192.168.2.254, and another laptop with an IP Address of 10.10.60.8 in default VLAN port 23. I cannot ping past the Swithes 10.10.60.254 interface.
I know this may be a Dlink problem; but a few people have said that the Pix may not understand anything coming from the 192.168.X.X subnet since it isn't a VLAN of the Pix.
I have tried setting up a 192.168.2.0 host/network and a 192.168.2.1 VLAN on the inside interface of the Pix. I have tried pinging anything outside of my 10.10.60.254 and still to no avail.
I just want the 192.168.2.X network to be able to see all VLANs (Which it can as long as it is internal to the switch) and also be able to connect to the internet.
I have tried setting static routes in the DLink a couple of ways such as 192.168.2.0/25 DGW: 10.10.60.254, 192.168.2.0/24 DGW: 10.10.60.X (the switches DGW), 192.168.2.0/24 DGW: 192.168.2.1 (The Pix's VLAN inside Interface) all will not allow connectivity to internet.
I could just set all to 10.10.60.X since it is a small company; but now it has be come a spite/general cause issue.
Any help or questions on will be greatly appreciated.
Scenario:
1. Pix 506e - IP External: 209.XXX.XXX.XXX, IP Internal: 10.10.60.X
2. A DLink 3326SMR layer 3 switch with default VLAN - ports 23-24, IP: 10.10.60.254, VLAN2 - ports 1-4, IP: 192.168.2.254
Default Gateway for Default VLAN 10.10.60.X from Pix 506e. RIP is enabled and have set up Group VLANs to dynamically join other VLANs.
Here is my problem. I can from the switch ping the interface addresses of both VLANs (10.10.60.X, 10.10.60.254, 192.168.2.254) and can ping a laptop with an IP Address of 192.168.2.8 in port 1 on VLAN2.
From the laptop 192.168.2.8 I can ping 10.10.60.254, 192.168.2.254, and another laptop with an IP Address of 10.10.60.8 in default VLAN port 23. I cannot ping past the Swithes 10.10.60.254 interface.
I know this may be a Dlink problem; but a few people have said that the Pix may not understand anything coming from the 192.168.X.X subnet since it isn't a VLAN of the Pix.
I have tried setting up a 192.168.2.0 host/network and a 192.168.2.1 VLAN on the inside interface of the Pix. I have tried pinging anything outside of my 10.10.60.254 and still to no avail.
I just want the 192.168.2.X network to be able to see all VLANs (Which it can as long as it is internal to the switch) and also be able to connect to the internet.
I have tried setting static routes in the DLink a couple of ways such as 192.168.2.0/25 DGW: 10.10.60.254, 192.168.2.0/24 DGW: 10.10.60.X (the switches DGW), 192.168.2.0/24 DGW: 192.168.2.1 (The Pix's VLAN inside Interface) all will not allow connectivity to internet.
I could just set all to 10.10.60.X since it is a small company; but now it has be come a spite/general cause issue.
Any help or questions on will be greatly appreciated.