Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations derfloh on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

help installing pix 506E in current setup?

Status
Not open for further replies.

cDc23

Programmer
Feb 3, 2003
1
GB
Hi all - forgive my lack of knowledge in this area (I understand only the basics). My setup is as follows:

current setup:

- 2 x ISP managed load balanced routers (currently default gateway .254) which hook into a switch.
- a range of internet facing IP addresses .1 - .253 of which all our office machines and servers are assigned one
- multiple web servers each assigned an internet facing IP

I have purchased a PIX 506E with the intention of "firewalling" our network and I have an IP address available for the outside interface.

is it possible to connect it as follows:

routers -- switch -- pix --- switch --- lan

and then configure the PIX to work with my ip range assigned by the ISP bearing in mind my web servers need to keep their current IP addresses (however my office machines could in theory be switched to work off DHCP provided by the pix but not the servers). I could give the servers an internal "192.168" address and map the external IP numbers in some way to the right servers that would also work but configuring the PIX is of course tricky having not done this before.

one other thing that is kind of weird - i plugged my primary router directly into the outside interface socket of the PIX just to see if it worked and the interface lights did not come on however the primary router connected straight into the switch is OK - does the cable have to be crossover?

I appreciate without further details of the exact current configuration advice is difficult - but if you can offer any advice on what configuration options I need to be looking at and any URLs I can look at would be great!

oh yes, would be using the PDM (PDQ??) web interface to configure!!!

any advice on this would be most appreciated

Cheers
cdc
 
HI.

> I have purchased a PIX 506E
Did you consider purchasing a pix515 with 3 interfaces so one of them can be a DMZ to connect the web servers?
It might be too late or not relevant, or is it an option?

> is it possible to connect it as follows:
> routers -- switch -- pix --- switch --- lan
Yes. But IP addressing will need modifications, as you already have mentioned.
The routers have a common ip address, the .254 right?
Because the pix can use only 1 default gateway.

> I could give the servers an internal "192.168" ...
Yes, that is the basic standard design.

> does the cable have to be crossover?
Yes, the pix 506 interfaces act like a host, not like hub/switch.

You can find here some links that I have gathered:
The first one will lead you to a lot of further info:

One of the main tools for pix management is syslog messages, so get to know and use them:

Good luck
Yizhar Hurwitz
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top