11-16-2006 04:24 AM - edited 03-11-2019 01:56 AM
Hi,
Whether PIX501 supports DMZ interface ?. I know that PIX501 has 1 outside interface along with 4 build-in ethernet port. can we use any one the 4 port as DMZ interfaces ? If not can you please tell me which model of PIX supports DMZ interfaces .
--Jaffer
Solved! Go to Solution.
11-16-2006 05:21 AM
The 4-port card on PIX501 is similar to switch port. All ports belongs to the same inside segment. You cannot use any of them for DMZ or run as individual/independent port, i.e used as DMZ segment.
To get PIX that support DMZ, try to get PIX515E with at least 1 x 10/100Base-T port card. You can use PIX515E with default Restricted (R) license with max 3 interfaces. f you need more interfaces, get Unrestricted (UR). This UR license support more 10/100Base-T ports
- check under LICENSE OPTIONS:
Pls rate all useful post(s)
HTH
AK
11-16-2006 05:21 AM
The 4-port card on PIX501 is similar to switch port. All ports belongs to the same inside segment. You cannot use any of them for DMZ or run as individual/independent port, i.e used as DMZ segment.
To get PIX that support DMZ, try to get PIX515E with at least 1 x 10/100Base-T port card. You can use PIX515E with default Restricted (R) license with max 3 interfaces. f you need more interfaces, get Unrestricted (UR). This UR license support more 10/100Base-T ports
- check under LICENSE OPTIONS:
Pls rate all useful post(s)
HTH
AK
11-16-2006 07:21 AM
By default, PIX515E comes with 2 x FE port. Get 1 additional FE card to have max 3 interfaces supported under Restricted (R) license.
HTH
AK
11-16-2006 07:13 AM
The short answer to your question is no, the PIX 501 does not support a DMZ interface (like a Linksys router/switch does). The PIX 506 does not either.
To get to a PIX with a DMZ interface, you need a PIX 515e or greater with the correct number of interfaces in it.
11-16-2006 08:02 PM
Hi,
I think that link is only accessible to channel patners only because my CCO user name is not working .Any have now I am clear that switch ports can not be used as 'DMZ' ports. Thanks a lot .
--Jaffer
11-22-2006 06:02 AM
Sorry for the late reply, but if you ever came across such link with 'partner' keyword, the trick is to delete the keyword, as follow:
Before:
After:
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_data_sheet09186a0080091b18.html
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_data_sheet09186a0080091b15.html
HTH
AK
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide