
Hosts/Networks>Add>Static Route
Unless one of the following criteria is met (in which case, click Next to skip this dialog box), you should define a
static route to ensure that the PIX Firewall unit correctly forwards network packets destined to the host or
network:
The network or host you are defining is connected directly to the selected interface
●
Dynamic routing is enabled for the interface to discover the routes
●
A more general static route, such as the default route, is already defined
●
After you enter the basic information for a host or network, PDM queries the current static routing table
(including directly connected networks) to determine how the firewall should route packets destined to the
specified IP address and mask. If the routing table query reveals that such packets are routed to an interface
different from the one specified in the Create host/network>Basic Information dialog box, PDM prompts you
to define a static route by displaying the Create host/network>Static Route dialog box. If you selected the
Never ask me this question again check box during this administrative session, PIX Device Manager does not
query the static routing table on the PIX Firewall, and skips the Create host/network>Static Route dialog box.
You can also use a static route to override any dynamic routes that are discovered for this host or network by
specifying a static route with a lower metric than the discovered dynamic routes. To create a static route for a host
or network, you must define the IP address and metric for the hop gateway to which the PIX Firewall will
forward packets destined to the selected host or network. You can also define multiple static routes for a host or
network. To do so, complete the Create host/network Wizard, and then add additional routes using the
Routing>Static Route panel on the System Properties tab.
The following sections are included in this Help topic:
Field Descriptions
●
Defining Static Routes
●
Field Descriptions
The Create host/network>Static Route dialog box displays the following fields:
Define Static Route—Select this check box to define a static route for this host or network.
●
Gateway IP Address—Identifies the IP addresses of the default gateway (or the next hop gateway) that
forwards any network packets destined to this network or host.
●
Metric—Identifies the priority for using a specific route. When routing network packets, a PIX Firewall
unit uses the rule with the most specific network within the rule's definition. Only in cases where two
routing rules have the same network is the metric used to determine which rule will be applied. If they are
the same, the lowest metric value takes priority. If no routing rule exists, the network packet is dropped,
and if the gateway is not detected (dead), the network packet is dropped. A metric is a measurement of the
●
Summary of Contents for PIX 520 - PIX Firewall 520
Page 45: ...Copyright 2001 Cisco Systems Inc ...
Page 68: ...Copyright 2001 Cisco Systems Inc ...
Page 74: ...Copyright 2001 Cisco Systems Inc ...
Page 87: ...Copyright 2001 Cisco Systems Inc ...
Page 92: ...Copyright 2001 Cisco Systems Inc ...
Page 108: ......
Page 184: ......
Page 197: ...Copyright 2001 Cisco Systems Inc ...
Page 200: ......
Page 232: ...Copyright 2001 Cisco Systems Inc ...
Page 246: ...Copyright 2001 Cisco Systems Inc ...