ONT and Cisco PIX 501
harddrive747
Enthusiast - Level 3

Back in December, I wrote on this board about connecting a PIX directly to the ONT.  I was told that i could.  I have finally been able to get Business FIOS installed and it worked like a champ.  The Actiontec router worked great and everything is up and running with the Cisco PIX behind it.

Since I want to use the Actiontec as a wireless access point and at this time, I'm unable to do that because the wireless is in front of the PIX firewall.  Since I was told that I could go from the ONT to the PIX, I tired  that and it didn't work.

I took the ethernet out of the ONT and plugged it directly into the WAN port on the PIX.  When I did that, the PIX wouldn't connect.  There was a VPN that was suppose to be set up and it wouldn't connect.  We rescripted the PIX and it still wouldn't connect.  I attempted to connect through the PIX to the Internet and I couldn't.

What do I need to have change on the PIX to get it to get it to work without having the Actiontec between it and the ONT.

Thanks for letting me know

Terry

1 Solution

Correct answers
Re: ONT and Cisco PIX 501
dragon8452
Enthusiast - Level 2

I have had numerous problems with connecting anything non verizon to the ethernet port of my ONT.  After some trial with alot of error the problem that I found is this:

You MUST manually release the DHCP lease before you unplug and switch any equipment that aquires an IP address from the verizon network.  I have had an instance where failing to perform this step resulted in the inability for any device to reconnnect for over 24 hours, even with the network techs attempting to release the lease from there end.  This would definately result in all the lights looking good without giving you the end results.

View solution in original post

Re: ONT and Cisco PIX 501
Anti-Phish1
Master - Level 1

How was the Actiontec conntected to the ONT?  Via coax or cat5?  You did not specify.

  • If it is connected via coax, you can't simply plug in to the RJ45 on the ONT and expect it to work.  VZ has to change the provisioning from their end.
  • If it's a cat5 connection to the ONT, then do you have static IP address(es)?  Or DHCP?
  • If it's DHCP, then you probably didn't release the DHCP lease before switching connections.
  • If you have static IP addresses, then the router's MAC/IP pair address is still in VZ's ARP cache.  Turn everything off for 6 hours.  After that, you should be able to get a connection with a static IP address without having a MAC address conflict.
Re: ONT and Cisco PIX 501
harddrive747
Enthusiast - Level 3

It is connected via Category 5.  I also get it using DHCP.

So what you are saying is that I need to release the IP address on the Actiontec and then plug the ethernet cable into the PIX and it should get the IP address.

I will have to do that one day when I get back up that way.

Thanks.

Re: ONT and Cisco PIX 501
prisaz
Legend

You say you took the Ethernet out of the ONT to the PIX, was the Ethernet in use on the Actiontec WAN port before? If it was coax, you will need to get a repair ticket created so tech support can switch the ONT from MOCA to Ethernet. Both ports are not active. It is one or the other..

Now you may have had Ethernet to the WAN the whole time. Being an existing connection and depending where you are located, it could be your ONT is provisioned PPPoE, and not DHCP. If it is business class now, I would want DHCP, or a block of static addresses that are not blocked in any way, or listed as part of a pool that could be blacklisted for running a mail server. Business FiOS should give you staic IP. I believe they give you up to 4. Not sure. I would contact them to see how you are provisioned. Tech support should know.

0 Likes
Re: ONT and Cisco PIX 501
harddrive747
Enthusiast - Level 3

It was always connect Ethernet.  According to the Actiontec it gets it's IP address from DHCP.

I will try what the other poster said about releasing the IP address from the Actiontec and then plug in the PIX.  I think that may be the issue.

I will let you know what I find.

Re: ONT and Cisco PIX 501
prisaz
Legend

Was not sure. But yes he has some good ideas. I would think being business they would give you static IP. But yes what he said. Up until a few days ago, my primary router was a hardened linux box with Dans guardian proxy server. Now that sits behind the Verizon router because I want them to fix their TV features and keep them working.

0 Likes
Re: ONT and Cisco PIX 501
dragon8452
Enthusiast - Level 2

I have had numerous problems with connecting anything non verizon to the ethernet port of my ONT.  After some trial with alot of error the problem that I found is this:

You MUST manually release the DHCP lease before you unplug and switch any equipment that aquires an IP address from the verizon network.  I have had an instance where failing to perform this step resulted in the inability for any device to reconnnect for over 24 hours, even with the network techs attempting to release the lease from there end.  This would definately result in all the lights looking good without giving you the end results.

Re: ONT and Cisco PIX 501
Hubrisnxs
Legend
Re: ONT and Cisco PIX 501
prisaz
Legend

I guess I should be happy to still be PPPoE where I can just reconnect to my FiOS and get the old or new IP regardless of my MAC address. I have used just about everything you can think of as a router. Including a Linux box when is now sitting behine the Verizon router. So I hope you set your issues solved.

0 Likes
Re: ONT and Cisco PIX 501
harddrive747
Enthusiast - Level 3

I want to take a minute to thank you all for helping me out.  The members who said that I needed to release the IP address on the Actiontec and then plug into the firewall was correct.  Once I did that, the PIX got an IP address and is routing everything and it is working like a champ.

Again, thank you for all your help.