<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Getting Started with PIX 506 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/getting-started-with-pix-506/m-p/700689#M1009674</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;diagram is in his first post. it appears to be adsl router not modem. I assume 74.41.202.106 is the address on outside of router so he cannot make this pix outside.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 21 Mar 2007 16:23:01 GMT</pubDate>
    <dc:creator>acomiskey</dc:creator>
    <dc:date>2007-03-21T16:23:01Z</dc:date>
    <item>
      <title>Getting Started with PIX 506</title>
      <link>https://community.cisco.com/t5/network-security/getting-started-with-pix-506/m-p/700684#M1009664</link>
      <description>&lt;P&gt;First of all, thank you for remembering when you first started with PIX appliances...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I recently purchased a pre-owned PIX 506 running software version 5.1(2). I am currently unable to upgrade this software since I do not have the apprpriate 'service contract', so I am stuck with this software version.&lt;/P&gt;&lt;P&gt;Although I did receive the manual 'Configuration Guide for the Cisco PIX Firewall Version 5.1', I am a bit lost with this firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My network:&lt;/P&gt;&lt;P&gt;ADSL Router (ISP Provided) =&amp;gt;PIX=&amp;gt;Switch=&amp;gt;Network &lt;/P&gt;&lt;P&gt;  Subnet: 192.168.254.0/24&lt;/P&gt;&lt;P&gt;  Netmask: 255.255.255.0&lt;/P&gt;&lt;P&gt;  Static External IP assigned by ISP:74.41.202.106  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Questions:&lt;/P&gt;&lt;P&gt;1) The 'inside' interface should be a LAN assigned IP? (Ex. 192.168.254.3)&lt;/P&gt;&lt;P&gt;2) What should the 'outside' interface be set to? &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:50:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/getting-started-with-pix-506/m-p/700684#M1009664</guid>
      <dc:creator>srberg5219</dc:creator>
      <dc:date>2019-03-11T09:50:05Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Started with PIX 506</title>
      <link>https://community.cisco.com/t5/network-security/getting-started-with-pix-506/m-p/700685#M1009667</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Questions:&lt;/P&gt;&lt;P&gt;1) The 'inside' interface should be a LAN assigned IP? (Ex. 192.168.254.3)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Yes, inside interface should be in 192.168.254.0/24 subnet. You can choose any free IP and make it as the gateway for the internal network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) What should the 'outside' interface be set to?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- "Static External IP assigned by ISP:74.41.202.106", as this is the IP given to you by your ISP, this should be on the outside interface of PIX. However, they must have also provided the subnet mask and the gateway IP. Please use the subnet mask while configuring IP address on outside interface, and use the gateway_IP as such:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside 0 0 gateway_ip&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With this command in, PIX will know where to route traffic for internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vibhor.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2007 15:34:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/getting-started-with-pix-506/m-p/700685#M1009667</guid>
      <dc:creator>vitripat</dc:creator>
      <dc:date>2007-03-21T15:34:34Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Started with PIX 506</title>
      <link>https://community.cisco.com/t5/network-security/getting-started-with-pix-506/m-p/700686#M1009671</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) correct&lt;/P&gt;&lt;P&gt;2) If 74.41.202.106 is the ADSL router address, you should set the "outside" interface to an address in the same subnet of your ADSL Router. And your default gateway on your PIX will be the ADSL Router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2007 15:36:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/getting-started-with-pix-506/m-p/700686#M1009671</guid>
      <dc:creator>huynhkhay</dc:creator>
      <dc:date>2007-03-21T15:36:08Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Started with PIX 506</title>
      <link>https://community.cisco.com/t5/network-security/getting-started-with-pix-506/m-p/700687#M1009672</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is my subnet structure:&lt;/P&gt;&lt;P&gt;Router LAN IP: 192.168.254.1&lt;/P&gt;&lt;P&gt;* 74.41.202.106 IP is the static IP I lease from my ISP for access to my web servers/email servers FROM the internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I should set the following:&lt;/P&gt;&lt;P&gt;1) Inside Interface IP: 192.168.254.2&lt;/P&gt;&lt;P&gt;2) Outside Interface IP: 192.168.254.3&lt;/P&gt;&lt;P&gt;3) PIX Gateway IP:192.168.254.1 (since this is the LAN IP of the router)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My gartitude ahead of time...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2007 16:10:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/getting-started-with-pix-506/m-p/700687#M1009672</guid>
      <dc:creator>srberg5219</dc:creator>
      <dc:date>2007-03-21T16:10:44Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Started with PIX 506</title>
      <link>https://community.cisco.com/t5/network-security/getting-started-with-pix-506/m-p/700688#M1009673</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So I should set the following:&lt;/P&gt;&lt;P&gt;1) Inside Interface IP: 192.168.254.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Yes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Outside Interface IP: 192.168.254.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- No. The outside interface and inside interface cannot be in same subnet. You should use 74.41.202.106 on the outside interface of PIX and connect the outside interface to the ADSL modem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) PIX Gateway IP:192.168.254.1 (since this is the LAN IP of the router) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Not sure where is this router placed. Is your ISP terminating currently on this router? What type of connection do you have .. PPPoE/PPPoA/DSL etc?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, it seems that you already have a network setup with ISP terminating on the router and internal network connected to the 192.168.254.1 interface. Now you are trying to place a PIX in between. Let me know if this is the situation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vibhor.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2007 16:20:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/getting-started-with-pix-506/m-p/700688#M1009673</guid>
      <dc:creator>vitripat</dc:creator>
      <dc:date>2007-03-21T16:20:34Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Started with PIX 506</title>
      <link>https://community.cisco.com/t5/network-security/getting-started-with-pix-506/m-p/700689#M1009674</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;diagram is in his first post. it appears to be adsl router not modem. I assume 74.41.202.106 is the address on outside of router so he cannot make this pix outside.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2007 16:23:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/getting-started-with-pix-506/m-p/700689#M1009674</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-03-21T16:23:01Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Started with PIX 506</title>
      <link>https://community.cisco.com/t5/network-security/getting-started-with-pix-506/m-p/700690#M1009675</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This firewall is being integrated into an existing network where the router's IP (192.168.254.1) was set as the 'Default Gateway' on workstations and servers (Windows based) and as the 'forwarding' address in Windows DNS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Physically, here is my layout before PIX:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;===Internet===&lt;/P&gt;&lt;P&gt;     |&lt;/P&gt;&lt;P&gt;     |&lt;/P&gt;&lt;P&gt;===Router=== (LAN IP of 192.168.254.1)&lt;/P&gt;&lt;P&gt;     |&lt;/P&gt;&lt;P&gt;     |&lt;/P&gt;&lt;P&gt;===Switch=== (unmanaged)&lt;/P&gt;&lt;P&gt;     |&lt;/P&gt;&lt;P&gt;     |&lt;/P&gt;&lt;P&gt;===Network=== (Web/Email servers-IPs set)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am placing my PIX AFTER the router:&lt;/P&gt;&lt;P&gt;===Internet===&lt;/P&gt;&lt;P&gt;     |&lt;/P&gt;&lt;P&gt;     |&lt;/P&gt;&lt;P&gt;===Router=== (LAN IP of 192.168.254.1)&lt;/P&gt;&lt;P&gt;     |&lt;/P&gt;&lt;P&gt;     |&lt;/P&gt;&lt;P&gt;===PIX 506===&lt;/P&gt;&lt;P&gt;     |&lt;/P&gt;&lt;P&gt;     |&lt;/P&gt;&lt;P&gt;===Switch=== (unmanaged)&lt;/P&gt;&lt;P&gt;     |&lt;/P&gt;&lt;P&gt;     |&lt;/P&gt;&lt;P&gt;===Network=== (Web/Email servers-IPs set)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;**Connection type is PPPoA&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2007 16:29:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/getting-started-with-pix-506/m-p/700690#M1009675</guid>
      <dc:creator>srberg5219</dc:creator>
      <dc:date>2007-03-21T16:29:41Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Started with PIX 506</title>
      <link>https://community.cisco.com/t5/network-security/getting-started-with-pix-506/m-p/700691#M1009676</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;acomiskey is correct...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2007 16:30:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/getting-started-with-pix-506/m-p/700691#M1009676</guid>
      <dc:creator>srberg5219</dc:creator>
      <dc:date>2007-03-21T16:30:31Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Started with PIX 506</title>
      <link>https://community.cisco.com/t5/network-security/getting-started-with-pix-506/m-p/700692#M1009677</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the updates. However, in this scenario, we will have some major changes ..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As I mentioned earlier, outside and inside interfaces of PIX cannot be in same subnet, thus, if we place PIX in between, we will have to change the network addressing on whole internal network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;LAN IP of router will remain 192.168.254.1, which will also be the gateway IP of the PIX. You can assigne PIX outside interface any free IP in the same subnet. Now we need to give inside interface a totally new subnet and whole of your internal network will also be in the same new subnet as of PIX's inside interface. Let me know if this suits you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vibhor.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2007 16:36:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/getting-started-with-pix-506/m-p/700692#M1009677</guid>
      <dc:creator>vitripat</dc:creator>
      <dc:date>2007-03-21T16:36:20Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Started with PIX 506</title>
      <link>https://community.cisco.com/t5/network-security/getting-started-with-pix-506/m-p/700693#M1009678</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So if I understand correctly, this will be my setup:&lt;/P&gt;&lt;P&gt;1)Router IP: 192.168.254.1&lt;/P&gt;&lt;P&gt;2)PIX OUTSIDE interface: 192.168.254.2&lt;/P&gt;&lt;P&gt;3)PIX INSIDE Interface AND whole internal network: New subnet of 192.168.253.0/24.(or whatever new subnet I want to assign)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2007 16:46:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/getting-started-with-pix-506/m-p/700693#M1009678</guid>
      <dc:creator>srberg5219</dc:creator>
      <dc:date>2007-03-21T16:46:13Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Started with PIX 506</title>
      <link>https://community.cisco.com/t5/network-security/getting-started-with-pix-506/m-p/700694#M1009679</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If it were me, I would ditch the dsl router, get a dsl modem, assign 74.41.202.106 to the outside of pix, 192.168.254.1 to inside and be done with it. Then you won't have to change anything on the inside. Unless of course, you need an outside router. And it may have been easier to just change the transport network between the outside router and pix, rather than change your inside network. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2007 18:29:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/getting-started-with-pix-506/m-p/700694#M1009679</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-03-21T18:29:43Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Started with PIX 506</title>
      <link>https://community.cisco.com/t5/network-security/getting-started-with-pix-506/m-p/700695#M1009680</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My gratitude for everyone's time...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2007 20:16:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/getting-started-with-pix-506/m-p/700695#M1009680</guid>
      <dc:creator>srberg5219</dc:creator>
      <dc:date>2007-03-21T20:16:06Z</dc:date>
    </item>
  </channel>
</rss>

