Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Question regarding home lab and PIX device.

Status
Not open for further replies.

rob747

Technical User
Apr 23, 2008
2
US
I am in the process of building a home lab, I would like this lab to connect to my external Comcast internet connection and eventually connect everything up to this lab (About 10 PC's sometimes more depending on friends being over with laptops).

To get rid of my all in one Linksys device I was curious if it was possible to hook up a router in place of that Linksys all in one device to take care of NAT/Routing/DHCP ect. If so would I need a 12.4 capable router? Or can I use a PIX 501?

A PIX 501 with a 10 user license is definetly affordable even the 50 is in my price range however if I can I would opt for the 10 user license for price.

Is it possible to have a router NAT the inside LAN addresses into one address going to the PIX so that the PIX would only see one IP? Essentially I would still technically have 9 available. Do these licenses go by IP only or open sessions as well? If my router or 10 user PIX idea wouldn't work would the 50 user license be sufficient?

 
Either one would work. Your PIX is a dedicated firewall appliance that has a handfull of IPS signatures. The router, with the right IOS, will do the same and depending on flash and DRAM, will be able to load a lot more IPS signatures. I say "with the right IOS", because you will need an advanced IOS for security services to give you the firewall/IPS level of protection.

If you have neither and are looking to purchase new, then you might want to look at an ASA5505 since the PIX is end of life (you might not be able to purchase license to get to 50 if your buying used). You have no user license limit with the ASA's, just throughput limits.
 
I personally would pick up an 1811 router. it's got 2 FE ports, and a built in 10/100 8port switch. best of all witht he right licensing it's got firewalling capability, and is 12.4 capable (i'm running 12.4(15) on all of mine) they are a bit more spendy but i'm sure you can find one on e-bay for dirt.
 
did I mention there is a wireless option on this router as well. Helps with those pesky laptops =)
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top