Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

PIX 515E 7.1 add DMZ

Status
Not open for further replies.

wilson2468

Technical User
Jun 2, 2006
84
US
I have a PIX 515E with 7.1 set up in tandem with another and configured for stateful failover.

There are six interfaces total and four are being used:
Inside
Outside
customer
failover

The customer interface is set up in a DMZ sort of scenario with a security level of 10.

What I want to do is add a DMZ to the firewall for an FTP server.

I am not wanting to disturb any of the existing config as far a security policies go at the momment.

I have started to add the DMZ interface with IP address and a warning comes up that changing the security levels of interfaces can prevent traffic from entering or leaving interfaces.

I want to give the security level of the DMZ a 10 also.

My questions are:

If I add this interface and start to configure it, am I in danger of stopping the traffic through the existing config?

Can this be done on the fly, or is it something that you have to really be careful with?

What if I am not going to enable it just yet?

Can I give the new DMZ the same security level of the other customer Interface?
 
all I find regarding this is this:
PIX interfaces have an associated security level. Two interfaces at same level can't send packets to each other.

To let traffic flow from a high security level to a lower level, use the nat and global commands. For the opposite direction, from lower to higher, use the static and access-list commands.

Don't know if that helps any

Norm
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top