Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chris Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

complete novice havin real problems with pix 515

Status
Not open for further replies.

Rythum

IS-IT--Management
Dec 19, 2002
1
GB
Hi there,

i'm in desperate need of some major help, my MD has decided to purchase a PIX 515E Firewall, but in his great wisdom declined to take the install deal the reseller offered, and instead said that I (network novice and wed designer) can install and configure the unit. now i've managed to get the unit installed to a degree, it's in place and all the network can still see each other, but my problem is, once i plug the unit in, not a single user can get the internet, i've been through PDM and most of it makes no sense to me at all, below is the whole setup:-

ISDN 128k connection via,
Asus ISDNlinkRouter, settings as follows:-
INTERNET PAGE
IP Address from ISP = Dynamic
DNS IP Address = 194.74.65.68
Telephone = *******5987
LAN PAGE
Device IP = 192.168.0.254
Network Mask = 255.255.255.0
DHCP = Disabled
DNS IP = 1. 194.72.9.34
2. 194.74.65.68
3. 195.182.170.180

PIX settings
Enable password = password
Clock = UTC
Inside IP = 192.168.0.100
Inside Network Mask = 255.255.255.0
Host Name = Primetake-pix
Domain name = primetake.co.uk (network is not set up as a domain, but as a workgroup)
IP of HOST running PIX device manager = 192.168.0.113

PDM settings (to the best of my abilities) :-
ACCESS RULES PAGE
Access Rules
Source = Any
Destination = Any
Interface = inside (Outbound)
Service = ip
Description = Implicit Outbound Rule

TRANSLATION RULES
Type = Dynamic
ORIGINAL
Interface = inside
Address = inside: any/0.0.0.0
TRANSLATED
Interface = outside
Address = 127.0.0.1 (interface PAT) 192.168.0.101-192.168.0.150

HOST NETWORKS PAGE
Interface = inside
192.168.0.0 linked to 192.168.0.113
Interface = outside
127.0.0.1

SYSTEM PROPERTIES
All default settings

MONITORING
All default settings

If anyone can help with me see the internet again, I would be very very very grateful…..
 
HI.

Installing the pix in the network requires reconfiguration of either the ISDN router (preferred) and/or the internal ip addressing on the computers, in addition to the configuration of the pix itself.
Detailed planning is essential for proper implementation.
> (network novice and wed designer)
I suggest that you don't continue with this project by yourself. However if you're going to manage the pix later, it is good that you will be involved in the details of the planning and installation process.
It is beter to tell your manager "I'm not suitable for this", rather then getting blamed for all the problems that can and will happen.

I suggest the following:
1) Contact the ISP, asking to switch from single dynamic IP to a range of fix 8 or 16 ip addreeses, and to disable NAT on the router. This will be the change on the router but it should be done in the same time of the pix installation.
2) Get the installation deal from your reseller, your ISP, or 3rd party.

Bye
Yizhar Hurwitz
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top