Vlan and Firewall

Sid.lochan_at_gmail.com
Date: 09/19/05


Date: 19 Sep 2005 00:15:24 -0700

Hi ,

I know a little about firewalls. In my new company right now we have
150 systems including servers behind 198.168.165.0 IP range. We have a
PIX 501/IOS 6.2-firewall which protects us. Now i have been told to
create vlans for 5-6 departments as well as one vlan for servers with
access limited to some vlans.We have 7 2950 series swtichs.
I want to know that
1. Do i have to change setting in PIX too for Vlans.?Will firewall be
able to see all diffrent VLANS under 1 ip range that is 192.168.165.0
or i have to add some entries into it?(please also give EG
configuration if i needed that).

2. IF i created vlans on switches then how i'll direct them to use
Firewall to gain access to VPN and Internet.?

Please Help me and also guide me about what configurations i shud use.
Thanks in Advance.



Relevant Pages

  • Re: Vlan and Firewall
    ... PIX questions are usually better put to comp.dcom.sys.cisco. ... Do i have to change setting in PIX too for Vlans.? ... :Firewall to gain access to VPN and Internet.? ... or layer 3 switch such as a Cisco 3550 or Cisco 3750. ...
    (comp.security.firewalls)
  • Opinions on a VPN device for 10 concurrent users (25 total)
    ... integrated mode (another firewall). ... by using ISA and PPTP after configuring the PIX for passthrough. ... application servers. ...
    (comp.dcom.sys.cisco)
  • Re: Weird DNS behavior
    ... I made the change on my PIX and surely, ... All my DNS servers are behind a firewall and, ...
    (microsoft.public.windows.server.dns)
  • RE: [fw-wiz] separating the servers on a switch
    ... You could also use a firewall that lets you set policies between VLANs ... > downlink servers. ... paketfilters and give each server a seperate interface on that firewall. ...
    (Firewall-Wizards)
  • Re: CISCO PIX hard question, can you answer it? TIA
    ... :> When a user from inside the firewall attempts to ... A PIX with no DMZ and 10 users and servers would tend to imply a PIX 501 ... Life is a freak. ...
    (comp.dcom.sys.cisco)