Re: Can Cisco Pix be used as a router and a firewall?

From: Walter Roberson (roberson_at_ibd.nrc-cnrc.gc.ca)
Date: 10/17/05


Date: Mon, 17 Oct 2005 16:08:29 +0000 (UTC)

In article <1129548580.506259.71580@z14g2000cwz.googlegroups.com>,
EdD <edd@mredd.co.uk> wrote:
:I am after a hardware filewall and a router and was wondering if I
:could use a cisco Pix (probably 501) to route between 2 different
:subnets or vlans and to also be a firewall between those 2 subnets or
:vlans?

For the PIX 501, only if one of the subnets is internal and the other
is external. The PIX 501 does not support more than inside + outside
interface, and does not support VLANs, and does not support routing
on the same interface going back again.

The next model up, the PIX 506E, supports 2 VLANs that can be attached
to the inside interface, giving you a total of 3 logical interfaces
on the one physical interface. That would handle what you asked for,
provided that you have an inside 802.1Q compatible switch (or host NICs.)

The models above that get increasingly more flexible, expecially with
the new PIX 7.0 software; 7.0 is not available on the PIX 501 or 506/506E.

-- 
   Okay, buzzwords only. Two syllables, tops.  -- Laurie Anderson


Relevant Pages

  • Re: 2 IP ranges on PIX WAN
    ... create up to 2 logical interface per physical interface. ... does not support VLANs ...
    (comp.dcom.sys.cisco)
  • em, vlan and pf troubles
    ... I am having a problem with 5.3 release with pf, vlans and the em device. ... vlan interface on the machine eg ... <ACPI PCI bus> on pcib0 ... 2 ports with 2 removable, ...
    (freebsd-net)
  • Re: Welche Netzklasse ist die richtige.
    ... Clients ebenfalls in mehrere VLANs logisch strukturiert. ... ganze über ein ISA Interface, welches am Core Switch in alle VLANs getagged ... Standort groß genug auslegen, um nicht irgentwann einmal ein Resubnetting ... Du meinst sicherlich Ether-Interface nicht ISA ?:) ...
    (microsoft.public.de.german.windows.server.networking)
  • Re: bandwidth shaping traffic from/to specific subnet
    ... but it may not be the easiest way for you because a quick test I just did means that it looks like you can attach qdiscs to vlans directly. ... If this were not the case than what you would have needed to do is filter on the real interface. ... The protocol ip refers to the ethertype protocol number in the eth frame - it is possible to filter types other than ip, protocol all gets everything, others I can think of by name - arp,ipv6,8021q or you can just use the number direct. ...
    (comp.os.linux.networking)
  • Re: Two ips
    ... If each subnet has its own hub, then yes, the router interface on each hub ... subnet is configured to listen for packets on that subnet only. ... Each of the subnets now ...
    (comp.unix.solaris)