I'm in a situation where I have to support 2 configurations with our Pix. I don't have much time to get this working, and I question whether or not the new proposed configuration is even workable. I would really appreciate it if one of you experienced Pix and networking folks could take a quick peek at the configuration below and let me know if it will work. I apologize for the crude drawing, but I hope it will be sufficient. I guess my problem is with daisy chaining the 2950's together.
--------
Internet
--------
|
v
---------
cisco dumb
switch
----------
|
v
----------
Pix 525 Version 6.3
----------
|
v
----------- -----------
cisco 2950 |----------->cisco 2950
dumb hub | -------------
------------ |
| |
v v
----------- --------------
10.1.10.0 10.1.30.0
Load Balancer Load Balancer
------------ -------------
----------- -----------
cisco 2950 |----------->cisco 2950
dumb hub | -------------
------------ | | |
| | |
v v v v v v
3 or more servers 3 or more servers
10.1.10.2 10.1.30.2
10.1.10.3 10.1.30.3
10.1.10.4 10.1.30.4
1. Any host from the internet needs to access a server
in the .10 and .30 subnet.
2. Of course, the .10 and .30 need access to internet.
3. Servers in the .10 and .30 subnet need access to each
other
4. Access to servers will be via ports 389, 636, or 443.
For some reason, I don't think this configuration will work without adding an additional interface to the Pix.
Any help or suggestions will be greatly appreciated. I
cannot replace the 2950 with switches.
Thanks!
Yowza
--------
Internet
--------
|
v
---------
cisco dumb
switch
----------
|
v
----------
Pix 525 Version 6.3
----------
|
v
----------- -----------
cisco 2950 |----------->cisco 2950
dumb hub | -------------
------------ |
| |
v v
----------- --------------
10.1.10.0 10.1.30.0
Load Balancer Load Balancer
------------ -------------
----------- -----------
cisco 2950 |----------->cisco 2950
dumb hub | -------------
------------ | | |
| | |
v v v v v v
3 or more servers 3 or more servers
10.1.10.2 10.1.30.2
10.1.10.3 10.1.30.3
10.1.10.4 10.1.30.4
1. Any host from the internet needs to access a server
in the .10 and .30 subnet.
2. Of course, the .10 and .30 need access to internet.
3. Servers in the .10 and .30 subnet need access to each
other
4. Access to servers will be via ports 389, 636, or 443.
For some reason, I don't think this configuration will work without adding an additional interface to the Pix.
Any help or suggestions will be greatly appreciated. I
cannot replace the 2950 with switches.
Thanks!
Yowza