snailworks
Technical User
I am a 'newbie' to PIX and have an issue as to where my PIX needs to be placed within our network. The original installer set it up in one manner and a consultant stated that it it wrong. With all of the reading I have done, I cannot seem to find a scenario or example that is similar to ours.
This is what I have.
-A main location with our mail & file servers has a T1 Frame with a pvc to our ISP.
-3 branch locations each on their own T1 frame. Their pvc's route all traffic to the main office to share the same Internet connection.
-All internal machines are private-IP'd (10.0.[0-3].xxx depending on the branch)
Currently, the T1 Frame with the Internet is connected to a Cisco 2600. The 2600 is supposed to separate the Internet and Local IP traffic. Local traffic is passed directly to the switch where all workstations and servers connect. Public traffic is sent thru the PIX before connecting to the same switch.
Something like this...
Internet
|
Branch 1 \ | /I-net -PIX \ /PCs
Branch 2 > frame cloud > 2600 -switch-mail
Branch 3 / \ Local / \FileSvr
Can the 2600 with it's two inside ports be set up to split WAN (Frame) and Internet traffic?
Is this where and how the PIX should be placed?
If so, does the scenario I listed above seem like it should work?
I really need some help on this. My knowledge on this is not enough to make a decision as to how to progress. Any and all suggestions are welcome???
Thanks in advance,
Gary
This is what I have.
-A main location with our mail & file servers has a T1 Frame with a pvc to our ISP.
-3 branch locations each on their own T1 frame. Their pvc's route all traffic to the main office to share the same Internet connection.
-All internal machines are private-IP'd (10.0.[0-3].xxx depending on the branch)
Currently, the T1 Frame with the Internet is connected to a Cisco 2600. The 2600 is supposed to separate the Internet and Local IP traffic. Local traffic is passed directly to the switch where all workstations and servers connect. Public traffic is sent thru the PIX before connecting to the same switch.
Something like this...
Internet
|
Branch 1 \ | /I-net -PIX \ /PCs
Branch 2 > frame cloud > 2600 -switch-mail
Branch 3 / \ Local / \FileSvr
Can the 2600 with it's two inside ports be set up to split WAN (Frame) and Internet traffic?
Is this where and how the PIX should be placed?
If so, does the scenario I listed above seem like it should work?
I really need some help on this. My knowledge on this is not enough to make a decision as to how to progress. Any and all suggestions are welcome???
Thanks in advance,
Gary