judgestone
IS-IT--Management
I finally got my Pix to talk to my DLink Layer 3 switches VLANs and all VLANs can talk to each other and access the internet. Here is my problem.
-- We have two locations, each has a pix firewall. I have setup each location with a DLink Layer 3 switch with vlans. The two Pix's are connected through a site to site VPN. As long as you are on the default subnet, you can talk between both locations. If you are on any VLAN on either switch, the most you can do is talk to each other VLAN on the switch and connect to the internet; but cannot connect to any other VLAN on the other switch or connect to the other Pix directly.
Here is the setup:
Location 1 - Pix with outside interface - 209.XXX.XXX.XXX, inside interface 10.10.60.X, with a DLink Layer 3 switch connected to it with a default VLAN interface 10.10.60.254. The switch contains other VLANs, 10.10.66.X, 10.10.67.X, 10.10.68.X, and 10.10.69.X
Again all 66-69 can ping each other and the 60 interface and get to the internet no problem.
Location 2 - Pix with outside interface - 70.XX.XX.XX, inside interface 10.10.62.X, with a DLink Layer 3 switch connected to it with a default VLAN of 10.10.60.254. The switch contains other VLANs, 10.10.63.X, 10.10.64.X, and 10.10.65.X.
Again, 63-65 can ping each other and the 62 interface and get to the internet no problem.
They connected through a VPN with the 70 allowing connections from the 209 site.
I just want to be able to ping 10.10.63.X in location 2 from a 10.10.68.X in location 1 and so on. I cannot get the locations to talk. I thought it was a default gateway problem, but that doesn't seem to be it.
I have tried every concoction of rules and have yet to get the right one.
Any help in this matter will be greatly appreciated.
-- We have two locations, each has a pix firewall. I have setup each location with a DLink Layer 3 switch with vlans. The two Pix's are connected through a site to site VPN. As long as you are on the default subnet, you can talk between both locations. If you are on any VLAN on either switch, the most you can do is talk to each other VLAN on the switch and connect to the internet; but cannot connect to any other VLAN on the other switch or connect to the other Pix directly.
Here is the setup:
Location 1 - Pix with outside interface - 209.XXX.XXX.XXX, inside interface 10.10.60.X, with a DLink Layer 3 switch connected to it with a default VLAN interface 10.10.60.254. The switch contains other VLANs, 10.10.66.X, 10.10.67.X, 10.10.68.X, and 10.10.69.X
Again all 66-69 can ping each other and the 60 interface and get to the internet no problem.
Location 2 - Pix with outside interface - 70.XX.XX.XX, inside interface 10.10.62.X, with a DLink Layer 3 switch connected to it with a default VLAN of 10.10.60.254. The switch contains other VLANs, 10.10.63.X, 10.10.64.X, and 10.10.65.X.
Again, 63-65 can ping each other and the 62 interface and get to the internet no problem.
They connected through a VPN with the 70 allowing connections from the 209 site.
I just want to be able to ping 10.10.63.X in location 2 from a 10.10.68.X in location 1 and so on. I cannot get the locations to talk. I thought it was a default gateway problem, but that doesn't seem to be it.
I have tried every concoction of rules and have yet to get the right one.
Any help in this matter will be greatly appreciated.