Re: pix 506 config change help



wellingtonexternaltest@xxxxxxxxxxxxx wrote:


The current firewall config is shown below, [...]

Well, read the fine manual on www.cisco.com (I posted a link to the
documentation in my last article) and try to understand what each line of
the config you posted means. Then think about all that and try to find out
what that config lacks now and what it lacks, when you just change the
external IP address(es).

Sorry, but when I look at that config I get the strong feeling that you've
formerly been ripped off in quite an evil manner by someone who sold you
you a fancy device that was delivered to you basically with the factory
default configuration which does not even use more than 2% of what a pix
can do, but instead includes known buggy default pix settings like the
default fixup protocol stuff (something any skilled pix admin will switch
off first) and so on.

My advice is: Hire a *skilled* pix consultant and let him configure the box
according to your requirements, if you are not able to figure out the
problems of the config you posted yourself.

Wolfgang

.



Relevant Pages

  • Re: PIX 501 Verizon Infospeed DSL
    ... When you connect PIX 501 you cannot get to internet - correct? ... PIX 501 PPPOE config is incorrect or incomplete ... See Cisco doc "Configuring the PPPoE Client on a Cisco Secure PIX ... !--- Define the VPDN group that you use for PPPoE. ...
    (comp.dcom.sys.cisco)
  • Re: PIX 501 Verizon Infospeed DSL
    ... When you connect PIX 501 you cannot get to internet - correct? ... PIX 501 PPPOE config is incorrect or incomplete ... See Cisco doc "Configuring the PPPoE Client on a Cisco Secure PIX ... !--- Define the VPDN group that you use for PPPoE. ...
    (comp.dcom.sys.cisco)
  • Re: have PIX with VPN, need to obtain isakmp key
    ... Maybe if we use TFTP to copy the startup config to a server that will ... possible we need to get the existing isakmp key from the PIX. ... You've not clearly stated whether you are referring to the RSA keys used ... referring to a pre-shared key. ...
    (comp.dcom.sys.cisco)
  • Re: [fw-wiz] Pix rulebase/policy analysis
    ... You make very good points regarding the text editor, ... you have applied to the Pix. ... Personally I would rather the config be self documenting. ... I prefer the syntax validation of configuring at the command line rather ...
    (Firewall-Wizards)
  • Re: Pix Remote Assistance Problem
    ... I am a complete novice when it comes to PIX, if I'm honest I dont know ... what half the stuff means in the config, which is the root of my ... able to establish the connection to control the clients PC. ... the internet, how the client connects to the internet we can not ...
    (comp.dcom.sys.cisco)