Getting a new firewall

Posted on 2004-10-25
Last Modified: 2013-11-16
My home office firewall just died and looks like never coming back

I'm running off a UK broadband cable connection. I've just bought a Dlink DI-604 just to make sure I can get back on the net ASAP

I can get one of the following:

CISCO PIX 501 3DES Bundle (Chassis, SW, 10 Users, 3DES)

I thought I could put the DI-604 onto the cable modem and then untrusted users onto the DI-604, and isolate the development computers with the CISCO firewall for added security, so the WAN on the CISCO will plug into the LAN on the Dlink, and the WAN on the dlink into the broadband modem.

1. Any reason why this setup wouldn't work ?
2. Any reasons not to use a CISCO PIX in this configuration ?

Question by:plq
    LVL 11

    Accepted Solution

    1. No.

    2. No.
    LVL 13

    Assisted Solution

    Most people will use the "firewall" (i.e., NAT) capabilities of the D-link to provide security.     You are unique, given that you're actually purchasing a Cisco firewall product for your private network.   Impressive.

    It sounds like you're planning on putting the "good" users behind the PIX, and everyone else in a DMZ.   This should work fine, so long as you understand the network subnets and such.        The PIX line of firewalls is one of the most stable and secure that I know of.    I don't think you'
    ll have any problems.
    LVL 8

    Author Comment

    Thanks very much for the feedback

    I know the cisco inside the network is a bit extreme but I have computers the kids use, and I have sales people coming in now and again with all sorts of cr*p on their laptops. In addition if one or the other goes phut again I have a backup. Furthermore we VPN into clients networks quite a bit, so that can have a dedicated PC outside the cisco too.

    One thing, I think the dlink will be a 192.168 address, does that cause any problems if the cisco people are on 10. and the dlinks on 192. ?.

    Also more questions,
    3. will the cisco act as a dhcp server and
    4. would I need to put an windows server domain controller box inside the network.

    Sorry for being so dumb at networking ! 500 points is a lot of beer money though !
    LVL 15

    Assisted Solution

    No problem at all, the cisco will only route the traffic...

    3: yes, the cisco act as a DHCP server..
    4: and no, you do not have to install a windows server at all. the PIX is completly stand alone, and can act as a vpn device, and a dhcp server..
    LVL 8

    Author Comment

    Marvellous. Thanks for your help. Splitting points..
    LVL 8

    Author Comment

    And now its all working... didn't even need to RTFM !! thanks

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    How your wiki can always stay up-to-date

    Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
    - Increase transparency
    - Onboard new hires faster
    - Access from mobile/offline

    I found an issue or “bug” in the SonicOS platform (the firmware controlling SonicWALL security appliances) that has to do with renaming Default Service Objects, which then causes a portion of the system to become uncontrollable and unstable. BACK…
    The DROP (Spamhaus Don't Route Or Peer List) is a small list of IP address ranges that have been stolen or hijacked from their rightful owners. The DROP list is not a DNS based list.  It is designed to be downloaded as a file, with primary intention…
    After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
    After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

    856 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    17 Experts available now in Live!

    Get 1:1 Help Now