<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to get PIX (515) put between router and switch - design  in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-to-get-pix-515-put-between-router-and-switch-design-issue/m-p/199804#M629440</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;how able getting a cheap 1605 and using it as your gateway router and leave the entire setup inplace and just change the route statement on your current router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;then put the 1605 and the PIX infront of your network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;that would require the least amount of work. I would suggest getting a 2600 and using the CBAC since application layer filtering is love against virus's&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 31 Aug 2003 19:09:05 GMT</pubDate>
    <dc:creator>koaps</dc:creator>
    <dc:date>2003-08-31T19:09:05Z</dc:date>
    <item>
      <title>How to get PIX (515) put between router and switch - design issue...</title>
      <link>https://community.cisco.com/t5/network-security/how-to-get-pix-515-put-between-router-and-switch-design-issue/m-p/199802#M629438</link>
      <description>&lt;P&gt;Hello there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's more question of design, so I'd really appreciate any ideas. Basically we have a leased line connection, it's connected thru serial interface to 1721 router. There are 12 VLANs (subinterfaces) setup on internal router's ethernet interface and there is a HP layer2/3 switch connected to the router, which maintain all those VLANs. We have decided to put a firewall (PIX 515E) between a router and a switch - now the main question: how to implement it, and preferably, save existing VLANs. We have a small range of static IPs, but they are for serial router's interface only - the internal interface has non-routable IP range. &lt;/P&gt;&lt;P&gt;Is it possible to use the same IP address on both PIX's interfaces ? Or is there any other way to go ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Alexander &lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 06:57:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-get-pix-515-put-between-router-and-switch-design-issue/m-p/199802#M629438</guid>
      <dc:creator>anthony.barlow</dc:creator>
      <dc:date>2020-02-21T06:57:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to get PIX (515) put between router and switch - design</title>
      <link>https://community.cisco.com/t5/network-security/how-to-get-pix-515-put-between-router-and-switch-design-issue/m-p/199803#M629439</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You don't talk about inter-VLAN routing.  Here, i suppose you don't do it with the 1721.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One way to do what you are looking for is:&lt;/P&gt;&lt;P&gt;1- All 12 VLANs can be terminated into the PIX instead of 1721.&lt;/P&gt;&lt;P&gt;2- Then the PIX inside's IP addresses should be those actually assigned to 1721's e0 (including subinterface). That way, you don't have to reconfigure internal host's default gateway.&lt;/P&gt;&lt;P&gt;3- Now you need a new subnet between the PIX and the router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This design doesn't consider any public server, if any, that should be move in the DMZ.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 30 Aug 2003 21:11:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-get-pix-515-put-between-router-and-switch-design-issue/m-p/199803#M629439</guid>
      <dc:creator>bdube</dc:creator>
      <dc:date>2003-08-30T21:11:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to get PIX (515) put between router and switch - design</title>
      <link>https://community.cisco.com/t5/network-security/how-to-get-pix-515-put-between-router-and-switch-design-issue/m-p/199804#M629440</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;how able getting a cheap 1605 and using it as your gateway router and leave the entire setup inplace and just change the route statement on your current router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;then put the 1605 and the PIX infront of your network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;that would require the least amount of work. I would suggest getting a 2600 and using the CBAC since application layer filtering is love against virus's&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 31 Aug 2003 19:09:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-get-pix-515-put-between-router-and-switch-design-issue/m-p/199804#M629440</guid>
      <dc:creator>koaps</dc:creator>
      <dc:date>2003-08-31T19:09:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to get PIX (515) put between router and switch - design</title>
      <link>https://community.cisco.com/t5/network-security/how-to-get-pix-515-put-between-router-and-switch-design-issue/m-p/199805#M629441</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for answer,&lt;/P&gt;&lt;P&gt;what would you tell me about &lt;/P&gt;&lt;P&gt;"ip unnumbered" for Serial0 interface ? That way, I'd move routable network behind the router and in front of the PIX.&lt;/P&gt;&lt;P&gt;Another question - in order to use existing VLANs - do i just need a number of different IP addresses to set up on PIX's internal Ethernet interface? How many can i set up for 515E at all (maximum) ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Sep 2003 22:26:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-get-pix-515-put-between-router-and-switch-design-issue/m-p/199805#M629441</guid>
      <dc:creator>anthony.barlow</dc:creator>
      <dc:date>2003-09-01T22:26:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to get PIX (515) put between router and switch - design</title>
      <link>https://community.cisco.com/t5/network-security/how-to-get-pix-515-put-between-router-and-switch-design-issue/m-p/199806#M629442</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The ip unnumbered config looks perfect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, you just need a number of different IP addresses, one for each VLAN, to set up on PIX's internal interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But, there is a problem with the number of VLANs and the PIX model you have, the maximum described by Cisco is 8 VLANs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you decrease this number of VLANs by cascading some nets behind others?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Sep 2003 01:40:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-get-pix-515-put-between-router-and-switch-design-issue/m-p/199806#M629442</guid>
      <dc:creator>bdube</dc:creator>
      <dc:date>2003-09-02T01:40:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to get PIX (515) put between router and switch - design</title>
      <link>https://community.cisco.com/t5/network-security/how-to-get-pix-515-put-between-router-and-switch-design-issue/m-p/199807#M629443</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I spoke to Cisco support, it's possible to use PIX w/o VLAN setup, (part of tech article of &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/config/bafwcfg.htm#1113411" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/config/bafwcfg.htm#1113411&lt;/A&gt; &lt;/P&gt;&lt;P&gt;)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By default, with no VLANs configured, the PIX Firewall sends untagged&lt;/P&gt;&lt;P&gt;packets to any directly connected switch. If an untagged packet is received&lt;/P&gt;&lt;P&gt;by a switch on a trunk port, the switch forwards the packet on the native&lt;/P&gt;&lt;P&gt;VLAN assigned for that trunk port. By default, switches assign VLAN 1 to the&lt;/P&gt;&lt;P&gt;native VLAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm just wondering, in that case - how many IP addresses I can set up on PIX's ethernet interface ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Sep 2003 08:21:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-get-pix-515-put-between-router-and-switch-design-issue/m-p/199807#M629443</guid>
      <dc:creator>anthony.barlow</dc:creator>
      <dc:date>2003-09-03T08:21:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to get PIX (515) put between router and switch - design</title>
      <link>https://community.cisco.com/t5/network-security/how-to-get-pix-515-put-between-router-and-switch-design-issue/m-p/199808#M629444</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Anthony,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For security reason, you should not use VLAN 1, this one is normally reserved for switch management purpose only.  Also, this doesn't solve the issue to join your 12 VLANs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Koaps is proposing another solution who looks fine.  Read his post.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Sep 2003 13:18:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-get-pix-515-put-between-router-and-switch-design-issue/m-p/199808#M629444</guid>
      <dc:creator>bdube</dc:creator>
      <dc:date>2003-09-03T13:18:00Z</dc:date>
    </item>
  </channel>
</rss>

