02-28-2007 04:15 AM - edited 03-05-2019 02:37 PM
Hi all, i have some servers at work, on the same subnet as my other servers, i want to restrict traffic to 4 of them using a pix, I just want to restrict subnets, my question is would i need to put the pix in transparent mode? and do i need to put ip addresses on both in and outside interfaces on the pix? and if so how would people reach this as i dont want routing invloved as its on the same subnet!
hope you can help
thanks
Carl
02-28-2007 04:23 AM
Hi carl,
PIX does not support Transparent mode.
Rgds
Raju
02-28-2007 04:37 AM
Hi Raju
The pix does support transparent mode in version 7.0 upwards. So if you have a pix 515E or better running v7.0 you can do this.
Carl
Yes you can use the pix in transparent mode. The pix will have one IP address for management. You do not need to worry about routing as the hosts and servers are on the same subnet.
Attached is a link for v7.0 transparent configuration.
HTH
Jon
02-28-2007 04:48 AM
can i do this with a pix 501 with latest ios?
02-28-2007 04:53 AM
Carl
Unfortunately no. Pix 501 and Pix 506 do not support v7.0 and transparent firewall functionality is not available in v6.x.
You could look at using vacl's (vlan access-lists) which allow you to resrict traffic between hosts/servers within the same subnet.
HTH
Jon
03-06-2007 04:06 AM
Hi all, how can I filter traffic to these servers then if I do not have one of these firewalls, the servers are on the same subnet? any ideas what I can do here ?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide