[fw-wiz] PIX firewall licensing and beyond (newbie)

From: Vahid Pazirandeh (vpaziran_at_yahoo.com)
Date: 09/06/05

  • Next message: Firewall-Wizards: "[fw-wiz] Cisco Remote Access VPN Problem"
    To: firewall-wizards@honor.icsalabs.com
    Date: Mon, 5 Sep 2005 20:40:44 -0700 (PDT)
    
    

    Hello everyone,

    I come from a linux admin background and have an assignment to setup a pix
    firewall. This is new territory and will be my first time playing with pix os
    instead of iptables. Please excuse my newb questions, but we all start
    somewhere. :-)

    1. Which model? Our servers are in a co-location with a 100mbit drop. Would
    that make the 515E the right choice if we actually want to make use of our
    bandwith? The pix becomes the bottleneck?

    2. I'm a little uneasy about the licensing. What are the typical features I
    should make sure that are included (e.g., 3DES)? What should I watch out for.

    3. I read somewhere that vlan support is only in pix os 6.3. Is vlan support
    also based on which model I'm using, or do all pix firewall models have this
    feature?

    4. How many physical ports do the pix firewalls typically come with? It seems
    like it's 2: one uplink, one downlink. I can already think of 3 security
    levels that I want my servers separated into. Does that mean I have to buy
    expansion slots? Or should I use VLANs instead?

    5. Any recommendations on a location to order the pix firewall and licensing
    from? Good deals, good support, etc.

    6. Any recommendations on some online reading that will help with implementing
    the pix firewall? It would help to see some example network layouts to get a
    better idea of how the components should be pieced together.

    Here are a few places that I've already scoped out:
    http://www.netcraftsmen.net/welcher/papers/pix01.html (also:
    pix02-pix04.html)
    http://www.examcram2.com/articles/article.asp?p=101741&seqNum=1

    Your guidance would be very helpful. Thanks for a great mail list!

    A PIX student in training,
    -Vahid

    =============================================
     "Make it better before you make it faster."
    =============================================

            
                    
    ______________________________________________________
    Click here to donate to the Hurricane Katrina relief effort.
    http://store.yahoo.com/redcross-donate3/
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Firewall-Wizards: "[fw-wiz] Cisco Remote Access VPN Problem"

    Relevant Pages

    • Re: Kindly help me with this PIX problem
      ... If you have read the configuration that I posted, ... firewall configuration didn't change over many years and it did work ... PIX, our company cannot send or receive email. ... That command allows ssh to the PIX, ...
      (comp.dcom.sys.cisco)
    • Re: Firewall for laptops, corporation with 1,000 laptops
      ... I disagree completely that all you need is a PIX to protect your network, ... PIX does nothing to protect you from VPN ... alerting, which are essential to a firewall solution, are lacking.] ... the PIX firewall does nothing to protect a roaming laptop from ...
      (microsoft.public.security)
    • Re: Cisco PIX fixup protocol command
      ... The PIX is a stateful firewall and maintains state on ... The reason why a security evaluation might result in a recommendation to ... is no need to have the SMTP fixup enabled. ...
      (Security-Basics)
    • RE: Hardware Firewall vs Software Firewall
      ... Hardware Firewall vs Software Firewall ... will drive the price to the point where the PIX is more cost effective. ... on a router ACL unless you're using the CSPM, ...
      (Security-Basics)
    • RE: [fw-wiz] Skip the PDM
      ... PIX and CheckPoint and the PIX 501 is a real contender as a firewall to ... So to "speed things up" I tried using the PDM. ... DHCP pool starts at .2. ...
      (Firewall-Wizards)