cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
353
Views
0
Helpful
4
Replies

PIX 515E Cfgn - 2 Outside Int.

rkishanb
Level 1
Level 1

I have a PIX 515E Restristed Lic.

I have 3 int., 2 Otside and one Inside. Of the 2 Outside int, 1 is for a T1 and the other for DSL. Now, I have over 100 users. I want some of them to be directed to the int with T1 connection to the Internet and the remaining Users to be directed through the 2d (DSL) connection to the Internet. All users are in the 192.168.2.x /24 address range.

How can / will I implement this. Please help with any suggestions ASAP. Thanks.

kishan

4 Replies 4

nkhawaja
Cisco Employee
Cisco Employee

I was thinking of saying POLICY NAT. but this will not help, cause there can only be one active default route.

you can define two static routes (not the default route) but that will not serve the purpose either.

hmmm! the best approach i am thinking is to use PIX ver7.0, use multiple mode firewall with two contexts, one context for DSL users and other Context for T1 users.

This is just a suggestion, I am willing to see what other say on this.

thanks

Nadeem

Hello Nadeem:

Greetings and thanks for your reply to my posting.

I have 2 questions, which please bear with me.

1. Would you know if Using PIX v7 would help me accomplish this task, by

setting different Contexts?

2. Or, if I wanted to intorduce a router between the PIX and the Internal

hosts, would a Cisco R831 help me accomplish this? Or would I need a

higher model (since I want to, obviously, use the lowest model possible)

to implement this. Can I request you also to please suggest the configuration.

thanks,

kishan

1. PIX ver 7.0 will accomplish this task as i told you by creating multiple contexts for your users

2- cisco 831 is too small router, i would suggest to use 1700 router if you want to. but you can introduce it and see the performance

jackko
Level 7
Level 7

1. subnet 192.168.2.x/24 into smaller segments

2. deploy an internal router and apply source routing

i guess it all depends on how flexible you want it to be. for instance, 100 users needs to be divided into 2 groups. would you swap a user to a different group or it's fixed.

Review Cisco Networking for a $25 gift card