Ok I am kind of new to this. But I want to run this by some experts to see if I am right or if I am fundamentally incorrect.
I have 2 live networks to the internet on different IP ranges.
I just recently purchased 2 Pix 515 with failover and a 4 port card.
My network is currently live on the Internet. I would like to move it to a Private network, such as a 10.10.X.X network that is behind a firewall.
Here is the scenario.
I would setup the firewall to access the internet via one of the Live IP ranges.
Then I would like to keep the other Live IP range on the other port (such as the LAN port)
Then I would like to put all the workstations on a 10.10.221.x network connected to one of the ports from the 4 port card.
I would like to add all the servers to another port of that same card on a different address i.e. 10.10.220.x
Then I would like to create a DMZ on another port of that card that would support the Web servers (IIS, Apache, and OWA) and on network 10.10.222.x
And on the last port of the card I would like to create a test Server LAN on network 10.10.223.x
I am not sure if this is possible. Would the PIX act as a router? Or would I have to purchase other equipment. I would like to basically filter only necessary traffic to the servers. I also have to take into consideration that I have 2 outgoing trusts with our contractor’s networks.
Any and all comments and info would be very appreciated.
Since this is only a proof of concept I am open to some critique.
Thanks,
Tom
I have 2 live networks to the internet on different IP ranges.
I just recently purchased 2 Pix 515 with failover and a 4 port card.
My network is currently live on the Internet. I would like to move it to a Private network, such as a 10.10.X.X network that is behind a firewall.
Here is the scenario.
I would setup the firewall to access the internet via one of the Live IP ranges.
Then I would like to keep the other Live IP range on the other port (such as the LAN port)
Then I would like to put all the workstations on a 10.10.221.x network connected to one of the ports from the 4 port card.
I would like to add all the servers to another port of that same card on a different address i.e. 10.10.220.x
Then I would like to create a DMZ on another port of that card that would support the Web servers (IIS, Apache, and OWA) and on network 10.10.222.x
And on the last port of the card I would like to create a test Server LAN on network 10.10.223.x
I am not sure if this is possible. Would the PIX act as a router? Or would I have to purchase other equipment. I would like to basically filter only necessary traffic to the servers. I also have to take into consideration that I have 2 outgoing trusts with our contractor’s networks.
Any and all comments and info would be very appreciated.
Since this is only a proof of concept I am open to some critique.
Thanks,
Tom