Monday, February 16, 2009

PIX Firewall operating in one arm configuration

I have been befuddled once with setting the Cisco PIX/ASA in a one arm routing configuration. To picture below explains this:



Basically when you set the ASA as a default gateway, you are unable to have to ASA forward (or route) packets in and out of the same interface. This was the case in version 6.0 of the PIX OS. However with version 7.2(1) and later it can now be done via the command "same-security-traffic permit intra-interface".

A link with the how to can be found on the cisco website

No comments: