RE: Protecting PIX Firewall at the Perimeter Router

From: Piacquadio, Juan (juan.piacquadio@eds.com)
Date: 11/05/02


From: "Piacquadio, Juan" <juan.piacquadio@eds.com>
To: "'Naman Latif'" <naman.latif@inamed.com>, security-basics@security-focus.com
Date: Tue, 5 Nov 2002 13:41:43 -0500 

Naman,

I mean that using some access-lists as I can see that you did is just
enough. It is everything done.
Besides that you should avoid permitting icmp requests from the PIX and
through it.

Regards,

Juan

-----Original Message-----
From: Naman Latif [mailto:naman.latif@inamed.com]
Sent: Monday, November 04, 2002 10:47 PM
To: security-basics@security-focus.com
Subject: Protecting PIX Firewall at the Perimeter Router

Hi All,

I wanted some suggestions\practical experiences for protecting a
Firewall wall at the Perimeter Router Level.

We have a PIX Firewall connected to our Cisco Router, which is connected
to the Internet. Should there be any IOS Firewall Rules in the Router,
other than blocking Telnet,FTP etc to the Firewall itself ?

PIX will be doing NAT, protecting DMZ machines, and IPSec connections.

Regards \\ Naman



Relevant Pages

  • RE: Protecting PIX Firewall at the Perimeter Router
    ... Protecting PIX Firewall at the Perimeter Router ...
    (Security-Basics)
  • Re: What is the Pattern here ?
    ... These are all Dialup Connections that I had no connection with at the time. ... It's obviously an enormous security hole, ... > and a real firewall box. ...
    (comp.security.firewalls)
  • Re: Black Ice confesses faulty program!!!
    ... > outgoing connections or traffic except in cases where these connections ... > "dangerous/suspicious" traffic by the BlackICE program. ... > get into your machine then even a PC *without* a firewall is completely ... If you don't think "Spyware" is a problem for computer ...
    (comp.security.firewalls)
  • Re: Port 135
    ... The patch doesn't disable DCOM / RPC, so connections can still be made. ... That's why you need a firewall. ... the patch is not the thing to control ... control over your TCP/IP ports and services, ...
    (microsoft.public.security)
  • Re: Networking/Security Question...
    ... The router itself will be a Cisco 1721. ... >setup is very simple... ... XP sp2 having the firewall on by default. ... > # but deny established connections that don't have a dynamic rule. ...
    (freebsd-net)