Solved

PIX 515, Radware, PIX 501 and VPN - UPDATED

Posted on 2004-08-25
15
231 Views
Last Modified: 2013-11-16
Hello All,

I am looking for a sample config of something close to what is described below.

Here is my updated environment:

We have 2 T1's going into 2 1760 routers. We then connect these two routers to a Radware Linkproof device that aggregates both T's into one connection. This is for bandwidth management and load balancing. We want to then take a PIX 515 in put it on the other side of the Radware device.

We will use the PIX 515 for a DMZ as well.

The question I have pertains to the Radware device needing to do the NAT instead of the PIX.

Is this a problem?
Can I configure the PIX to allow for this?


The other part of this scenario is this:
We also have a DSL line coming in that management wants to use only for users to surf the web. We have a PIX 501 for this.

Are there any issues with this also?
0
Comment
Question by:cepolly
  • 8
  • 6
15 Comments
 
LVL 36

Expert Comment

by:grblades
Comment Utility
Hi cepolly,
> The question I have pertains to the Radware device needing to do the
> NAT instead of the PIX.
>
> Is this a problem?
> Can I configure the PIX to allow for this?
I can't forsee any problem with this. The PIX would just be configured without NAT and would probably have a private IP address on its outside interface. This wont cause any problems.

> We also have a DSL line coming in that management wants to use only for users to surf the web. We have a PIX 501 for this.
> Are there any issues with this also?
No problems with this. See my website for a configuration example:-
http://www.gbnetwork.co.uk/networking/ciscopixhomedsl.html
0
 
LVL 1

Author Comment

by:cepolly
Comment Utility
I'm not sure where this relates to the 2nd pix.
I followed your link and that works well for just the 501 alone.
I spoke to cisco and they said that having 2 PIXs on the same network doing what we want to do would cause issues.

I have already set up the PIX 515 and the RADware device and it is working well.
We are able to everything we need to. Email, web, internet and others.

Now I am trying to setup a a 2nd pix, a 501 to allow users onto the internet.
No incoming rules need be applied as all traffic inbound is coming in through the 515.

I was thinking of setting up the following:

dsl modem - outside interface: pppoe; inside interface: Bridge Mode
      |
      |
PIX 501 - outside interface: PPPoE; inside interface: 10.0.2.1
      |
      |
LinkSys DSL Router outside interface: 10.0.2.2; inside interface: 192.168.1.20
      |
      |
Internal Network - 192.168.1.0/25

Is this correct?
Is there anything I need to do on the Linksys to allow this to work?
0
 
LVL 36

Expert Comment

by:grblades
Comment Utility
You don't need the Linksys in there at all.

How are you going to setup the machines to split the traffic netween the T1 lines and the DSL?
You could have a proxy server and configure that machine to have the PIX501 as the default gateway.

What are the T1 lines being used for?
0
 
LVL 1

Author Comment

by:cepolly
Comment Utility
I don't have a proxy to set up.

as far as the t1's, this was a management decision to use them only for incoming web, mail, blackberry and a coupple of other external apps and for the servers to communicate out as well.

I wanted to use the dsl as a backup in case the t's, router or isp went down.

0
 
LVL 36

Expert Comment

by:grblades
Comment Utility
In that case it sounds like you can just set the default gateway on all the servers to be the PIX515 and have all the desktop machine use the PIX501 as the default gateway.
0
 
LVL 1

Author Comment

by:cepolly
Comment Utility
thats what I was thinking as well, but then I spoke with cisco and they came up with the problem that with this config, routing would be hosed. I am not sure how this would happen thought.
0
 
LVL 36

Expert Comment

by:grblades
Comment Utility
I can't see it being a problem as long as you don't have a machine which has to talk over the T1 and DSL lines.
0
Free Trending Threat Insights Every Day

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

 
LVL 1

Author Comment

by:cepolly
Comment Utility
update.

i installed it with the linksys and it is working.

thanks for the help.

0
 
LVL 36

Expert Comment

by:grblades
Comment Utility
Glad its working. If you are happy please accept one of the answers so the question can be closed.
0
 
LVL 36

Expert Comment

by:grblades
Comment Utility
I thought I had answered all the authors questions.

cepolly - Why did you go with the linksys instead of the PIX?
0
 
LVL 1

Author Comment

by:cepolly
Comment Utility
grblades, thanks for the help, but the recommendation to use the 501 for pcs, without the linksys, and the 515 for servers didn't work.

i also spoke to cisco and they said that this config would cause a 3rd leg scenario in that the return traffic would not know where to go.

i ended up using both the 501 and the linksys like this:

dsl modem - outside interface: pppoe; inside interface: Bridge Mode
      |
      |
PIX 501 - outside interface: PPPoE; inside interface: 10.0.2.1
      |
      |
LinkSys DSL Router outside interface: 10.0.2.2; inside interface: 192.168.1.20
      |
      |
Internal Network - 192.168.1.0/25

this setup worked.i point all pc's to the linksys.

let me know if i'm mistaken and i'll award the points based on consensus.

thanks,
cepolly

0
 
LVL 36

Accepted Solution

by:
grblades earned 500 total points
Comment Utility
The PIX wont route traffic back out the same interface or issue ICMP Redirect packets so adding the Linksys would mean that you could define the Linksys as the single default gateway for some machines and all traffic would go out of it.
On the linksys you could define a static route to some networks via the Radware box and any traffic for these the linksys would redirect to the radware (which the PIX would not do).

This is the only advantage that I can think of with adding the Linksys.

Return traffic wont be a problem since both Internet connections are using NAT so the reply will come straight back to the device performing the NAT and it will translate it and put the packet on the internal network.
0
 
LVL 1

Author Comment

by:cepolly
Comment Utility
"Return traffic wont be a problem since both Internet connections are using NAT so the reply will come straight back to the device performing the NAT and it will translate it and put the packet on the internal network."

you may have a point here. my intial setup did not use NAT through the radware device. this caused some other issues so I changed it to NAT through that Radware device.

i am wondering whether or not this may have caused traffic to cease when i added both PIX's.

from what i understand then, is that if we removed the radware completely from the picture, both pix's should work and pass traffic.

is this correct?
0
 
LVL 36

Expert Comment

by:grblades
Comment Utility
Yes it should work as long as the configuration is changed correctly.
The linksys should be the default gateway and have static routes applied to point to the PIX as the gateway for all IP's that should go via it.
0

Featured Post

Highfive + Dolby Voice = No More Audio Complaints!

Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

Join & Write a Comment

I recently updated from an old PIX platform to the new ASA platform.  While upgrading, I was tremendously confused about how the VPN and AnyConnect licensing works.  It turns out that the ASA has 3 different VPN licensing schemes. "site-to-site" …
To setup a SonicWALL for policy based routing to be used with the Websense Content Gateway there are several steps that need to be completed. Below is a rough guide for accomplishing this. One thing of note is this guide is intended to assist in the…
In this seventh video of the Xpdf series, we discuss and demonstrate the PDFfonts utility, which lists all the fonts used in a PDF file. It does this via a command line interface, making it suitable for use in programs, scripts, batch files — any pl…
You have products, that come in variants and want to set different prices for them? Watch this micro tutorial that describes how to configure prices for Magento super attributes. Assigning simple products to configurable: We assigned simple products…

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now