Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Cisco PIX 501 Lab review 1

Status
Not open for further replies.

Phantom309

Instructor
Jan 23, 2005
8
US
I've put together a PIX 501 Lab and would like some opinions on it's validity. The lab is designed to configure a PIX 501 with the 6 basic commands and allow ICMP to travel from point host A to Server B to test the configuration. I've tested the lab and it seems to work fine but it maybe missing something.

Any constructive input would be greatly appreciated. This is part of a capstone project for my BS degree in networking. This lab is the first in a series that I'll use to create a video training course for configuring the PIX 501 to complete my degree requirements.


Thanks in advance.

Phantom309
 
Looks nice, i like your step-by-step explanation and approach to configuring. One thing that i noticed is that you are using a pool of addresses, just keep in mind when using a pool with more than one address, you will not be using pat and as such, not many pc's will be able to communicate at once.

Jan


Network Systems Engineer
CCNA/CQS/CCSP/Infosec
 
Thanks Dopehead,

Could you elaberate just a little by saying how you would change the NAT address pool command syntax to use PAT instead of what is written? Thanks.

Phantom309
 
Well, if this config is supposed to support more simultaneous users than the ip addresses you have defined in your global statement, the pix needs to utilize Port address translation, ie nat'ing based on src addr/dest addr and src port/dst port instead, this will support many more users. Command would just be "global (outside) x x.x.x.x" instead , the pix will interpret this as that it is supposed to PAT and not dynamically one-to-one nat the hosts behind the pix.

Jan


Network Systems Engineer
CCNA/CQS/CCSP/Infosec
 
The Pix will use the last global address for PAT.
 
Since what version ? i have always had problems with session count when using a pool.

Jan


Network Systems Engineer
CCNA/CQS/CCSP/Infosec
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top