Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Westi on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

PIX 515E question.. thanks for any help provided!

Status
Not open for further replies.

gman10

Technical User
Jul 20, 2001
451
US
Hello all-

My boss just purchased a PIX 515 that will need to be installed at one of our customer site's (a school district) yuck! but anyway, here is the layout..

Currently, they had a WIndows Nt server w/ a software firewall application (Command View) running on it that crashed (blue screen), this server was attached to a Cisco 1601 router which routed out to a T1 (internet).. from the Windows NT server, there is a 2nd NIC card going to an Alcatel Omni Core switch(I know this is not the right forum for this so I'll keep this piece short) and now the school would like me to setup the PIX "in place" of the NT server w/ software firewall.. My question is, can someone map me a layout based on what I stated above as far as how things should connect together? Essentially, we have the 1601 router which has a NAT statement and is handling the internet, a PIX and an Alcatel OmniCore Switch (ESX 10/100 blade) 24 port switch.. I assume I don't really need to rebuild this Nt server that crashed since we've got the PIX. So would it look like this??

INTERNET
|
|
Router 1601----PIX 515E---alcatel switch...


Also, this school has VLANS so would I need to add any specific statements into the PIX to reflect VLANS on the Alcatel switch? I don't generally like using disparate products such as Cisco PIX and Alcatel switch because I never know what "gotchas" I'll face later.. Can anyone provide the pavement for my hurdles ahead?? Would I need that NT server connected to the PIX or router for any reason, it didn't serve any other purpose other that the "software firewall/internet services" for the district

thanks alot

gman[morning]
 
Your layout looks fine... Disable NAT on the router and have the PIX do the natting instead. If you are running 6.3 on the PIX then you should be able to configure VLANs on the PIX otherwise forget it. You do not need the server to filter traffic and act as a firewall that´s what the PIX is for.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top