
2-17
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 2 Establishing Connectivity
Configuring the PIX Firewall for Routing
Restrictions and Limitations
The PIX Firewall does not provide any filtering of OSPF in Version 6.3 beyond what is provided by
OSPF.
OSPF does not support dynamic routing over overlapping address spaces, so the PIX Firewall will not
support running OSPF on an interface from where it can learn overlapping addresses. To support
overlapping address networks, either configure static routes or use passive RIP.
Note Running both OSPF and RIP concurrently on the same PIX Firewall is unsupported.
Only broadcast networks are supported by the implementation of OSPF in PIX Firewall Version 6.3. The
following summarizes the OSPF features that are not supported by PIX
Firewall Version 6.3:
• Point-to-point link/serial interface/nonbroadcast multiaccess (NBMA)
• OSPF on demand Circuit
• Flood Reduction
area nssa
yes
ip ospf
message-digest-key
yes
show ip ospf
request-list
yes
area range
yes
ip ospf mtu-ignore
yes
show ip ospf
retransmission-list
yes
area stub
yes
ip ospf name-lookup
no
show ip ospf
summary-address
yes
area virtual-link
yes
ip ospf priority
yes
show ip ospf
virtual-links
yes
auto-cost
no (use
ospf cost)
ip ospf
retransmit-interval
yes
summary-address (OSPF)
yes
compatible rfc1583
yes
ip ospf transmit-delay
yes
timers lsa-group-pacing
yes
default-information
originate (OSPF)
yes
log-adj-changes
yes
timers spf
yes
distance ospf
yes
network area
yes
clear ip ospf
modified
ignore lsa mospf
yes
router-id
yes
default-metric (OSPF)
no
ip ospf authentication
yes
router ospf
yes
ip ospf demand-circuit
no
ip ospf
authentication-key
yes
show ip ospf
[process-id]
yes
ip ospf network
no
ip ospf cost
yes
show ip ospf
border-routers
yes
neighbor (OSPF)
no
ip ospf database-filter
yes
show ip ospf database
yes
1. The exact syntax for some commands used with PIX Firewall may differ slightly from the Cisco IOS software implementation. Refer to the Cisco PIX
Firewall Command Reference for the exact syntax of a specific command.
Note PIX Firewall does not accept spaces within OSPF authentication keys or message digests but Cisco IOS
does. This may create compatibility issues when a PIX Firewall tries to exchange OSPF messages if an
adjacent router uses spaces within its authentication key or message digest.
Table 2-4 Cisco IOS OSPF Commands Supported in PIX Firewall Version 6.3 (continued)
OSPF Command
1
Supported OSPF Command Supported OSPF Command Supported
Kommentare zu diesen Handbüchern