Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

PIX 501 and which routers to use for this setup?

Posted on 2004-11-23
8
Medium Priority
?
261 Views
Last Modified: 2010-04-17
I'm working on a Cisco home network so I can increase my overall networking skills.  This should be an easy question for you gurus.  I have a Cisco PIX 501 and I want to set up three completely different subnets internally.  I would like each of these subnets to have different rules in the firewall.  example follows:

10.1.100.0  255.255.255.0  DMZ1 with my web server (this server will be natted through the firewall) and can only be reached by coming in the firewall or through my home computer.  I dont want people to be able to access this server from my access point

10.1.200.0  255.255.255.0  DMZ2 with my wireles access point. I want this to be able to go out to the internet but not reach my home computers or my web server in DMZ1

10.1.300.0  255.255.255.0  inside with my home computers.  I want this to be able to reach the internet and DMZ1 where my web server sits but not the DMZ2.

The PIX 501 has an external ethernet interface and an internal ethernet interface.  the internal ethernet interface has a 4 port built in.  There are no other ports on the firewall except the console port.

So to my question:  How many routers do I need to make this happen?  And what kind?  I was looking at Cisco 2501 but they dont appear to have any way to interface with the PIX.  I'm sorry this is basic stuff, but I'm just getting in to this field.  I would assume the routers have to have ethernet inputs and ethernet outputs to do what i am asking but im not sure which routers i can use to do this.  Will a cisco 2505 work?  Any help will be appreciated.

To further help.... I have uploaded a picture of what I am trying to accomplish.  Check out this image to see what I am trying to explain poorly in this question:

http://www.geocities.com/bdhofmei/home.JPG
0
Comment
Question by:bdh113s
  • 4
  • 3
8 Comments
 
LVL 3

Assisted Solution

by:cnewgaard
cnewgaard earned 200 total points
ID: 12662155
On the 501 you're going to need a router for each subnet that you want to deal with.  You could use the 2500 series router you just need to have an aui to cat5 ethernet converter.  I'm sure you could probably find these on EBay or just do a search on AUI to Ethernet converter on the web.  If it's possible to get your hands on some 2600 series routers you could do this without the converter.  You could also purchase expansion modules on the 2600 that would give you enough ethernet ports to do it with one router.  
0
 
LVL 36

Expert Comment

by:grblades
ID: 12663045
Hi bdh113s,
You will need a 4 port router. Connect one interface to the internal interface of the PIX and the other 3 interfaces to the other networks that you want. A 4 port router is not going to be cheap. Bear in mond that you will need to configure a firewall on this router. If you want to go with Cisco then the smallest router you could use would be one of the 2600 series with an additional dual network module.
An old PC with 4 network cards running Linux would probably be the cheapest way to go.
0
 
LVL 2

Author Comment

by:bdh113s
ID: 12666682
Hey guys... Thanks for your input.  I'm going to increase the point value to 200 so I can split 100 to each of your answers.

cnewgaard... can you give a more specific answer to the exact model 2500s i could use. (lowest end for pricing reasons) and how this would work with the AUI converter.  I looked at the 2501 and saw an AUI port that could be converted to RJ45 but this would only handle the input.  How would you output traffic to the subnet that the 2501 would be routing traffic to?  So I stepped up to the 2505 router and I think it may work but I'm not sure if there are two seperate ethernet interfaces inside.

grblades... can you give more specifics on which 2600 and which modules i would have to grab in order to make this happen.  I know the linux box would work but im really trying to get in to cisco routing and i find i learn best when i just dive in with the hardware and start playing.
0
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 2

Author Comment

by:bdh113s
ID: 12666821
One more comment... the 2505 has 8 ethernet ports but i dont think those are seperate configuratble ethernet interfaces for routing traffic.  I believe its a built in switch with each of the ports labeled.  So perhaps the 2505 will not work.  If it will not work, which router will i need that has two seperate ethernet interfaces for routing traffic.  input from the firewall subnet on one ethernet interface and one output ethernet interface to a seperate subnet.
0
 
LVL 36

Expert Comment

by:grblades
ID: 12668293
I have had a look and you cannot get a 2 port network module by the looks of it so it would have to be a 4 port module (NM-4E) and in which case any of the 2600 series routers would be fine. The 2610 will be the cheapest.

No 2500 series router has more than 2 ethernet interfaces. There are models such as the 2516 but this is effectlvly 1 interface internally connected to a 16 port hub.
0
 
LVL 2

Author Comment

by:bdh113s
ID: 12668633
Thanks for baring with me on this guys, I appreciate the help.  I know none of them have more than 2 network interfaces.  But could I get 3 routers that have exactly 2 ethernet adapters?  Here is a good drawing of what I am trying to accomplish.  

http://www.geocities.com/bdhofmei/home2.JPG

Check out this image.  What is the least expensive router i can buy 3 of to accomplish this diagram.  OR What is the least expensive router that will do what I am trying to do in a single device.
0
 
LVL 2

Author Comment

by:bdh113s
ID: 12668648
Updated the points to 300 for all your trouble
0
 
LVL 36

Accepted Solution

by:
grblades earned 1000 total points
ID: 12669021
Yes you could do that. You would need 3 of either 1605R or 2514.

Another alternative would be to get a couple of 2514's or a couple of 1605R's plus serial WIC's and connect them together via their serial interfaces.

You could even get 4 2501/2503's and connect them together over the serial interfaces. Since each of them have 2 serial interfaces you can connect them in a loop and even play with routing.
The 2501 and 2503 were very common so can be found frequently and cheaply on ebay. You would just need 3 or 4 DCE-DTE serial cables for the 2500 series which are also often sold on Ebay.

One final way would be to get a router with at least 1 100Mbps interface (2620,2621,2650,2651) and connect it to a switch such as one of the 2900 series and configure trunking between VLAN's on the switch and the router. This is known as a 'router on a stick'. I would not advise it in a production enviroment in your situation since it is possible to flood the MAC table on the switch and bypass the router.
0

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The Cisco RV042 router is a popular small network interfacing device that is often used as an internet gateway. Network administrators need to get at the management interface to make settings, change passwords, etc. This access is generally done usi…
Creating an OSPF network that automatically (dynamically) reroutes network traffic over other connections to prevent network downtime.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

578 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question