05-11-2005 01:32 AM - edited 02-21-2020 12:08 AM
I am new to Cisco Pix and need to configure a 506e we have purchased to use a DMZ. Does anyone have a basic DMZ config I can work with. We have our internal network on 192.168.1.x and a Vlan on 192.168.2.x. We need access from internal out, and access from internal and external to DMZ.
Any help would be greatly appreciated.
We will also need to add access from external to our exchange server on internal network, and VPN to internal at a later date.
Nick
05-17-2005 06:57 AM
The Pix 506E has only two interfaces, inside and outside. But if you want to configure DMZ to Pix 506E, you need create VLANS, like a Virtual interface, here are links for the Vlan support and configuration.
http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/63rnotes/pixrn634.htm#wp159177
http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/config/bafwcfg.htm#wp1113411
05-17-2005 11:08 AM
Also, keep in mind that the vlan scenario doesn't work without using a vlan other than vlan1. I tried to use a "vlan1" as the physical interface on a 506e and traffic would not pass properly until I set it as VLANs 2 and 3. Odd.
05-18-2005 12:16 AM
According to the documentation, VLAN1 is always the default LAN, and so a DMZ must be setup on another VLAN to be separate from the LAN. I have my config running our main LAN as VLAN1, and my DMZ on VLAN2.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide