cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
193
Views
0
Helpful
1
Replies

Migrating from Chceckpoint to PIX 506

tony.hanson
Level 1
Level 1

I have a customer who has a Chcekpoint Firewall and they are looking to migtrate it to PIX 506. However, I just found out that they have 2 Internet connections coming in from the 2 different providers, also they have 2 different blocks of addresses one coming from each provider. What the customer was looking to do is us the 506, but I'm pretty sure he is going to need a 515 with multiple interfaces, but I just want to make sure. My other question would be - how many interfaces does he need? 3 or 4. He also is using the public addresses on all the devices on the inside. Any input would be helpful before this project gets rolling.

1 Reply 1

jsivulka
Level 5
Level 5

One option is to use the existing gateway router to terminate connections from the ISP's. The other option would be to use a higher end firewall such as 515. This would also mean using two perimeter routers. As far as the number of interfaces go, 3 on the 515 would be enough. However, from a scalability and good design (DMS etc) point of view, 4 would be better.

Review Cisco Networking for a $25 gift card