?
Solved

PIX Firewall Questions

Posted on 2005-03-18
5
Medium Priority
?
298 Views
Last Modified: 2013-11-16
One of our partner associations recommends that we install a PIX firewall to isolate the wireless AP's from the rest of the network. I have never setup a firewall and I am unclear of how the physical connection will take place.

All connectivity is run back to a central patch panel, and then connected to 3Com 3300 XM switches which are unmanaged. Since my switches are unmanaged, will I need to have a seperate switch for the AP's. There will only be two AP's( cisco aironet 1100 AP"s).
0
Comment
Question by:comtekso
  • 3
  • 2
5 Comments
 
LVL 10

Accepted Solution

by:
ruddg earned 1000 total points
ID: 13576921
Depending on the PIX firewall you select, you may have the following options:

1)

(Internet)----PIX515E----LAN switch---(LAN)
                       |
                "DMZ" switch
                       |
                Wireless APs

2)

(Internet)----(firewall/router)----LAN switch---(LAN)
                                                      |
                                                 PIX506E
                                                      |
                                                  Switch
                                                      |
                                               Wireless APs

The advantage of the first option is that the PIX can be leveraged for both Internet protection and isolation of your wireless deployment -- the PIX515E with a third interface, however, is more expensive than a two interface 506E.  (Note: If you have a small network with less than 50 wireless clients, and 4 or less APs, you can use a PIX501 and utilize the integrated hub ports on the PIX to connect to the APs directly.)

Also, while not recommended, you *can* technically use the same switch hardware for two different IP subnets.  There are security risks involved with this configuration, but it will work:

           SWITCH PORTS
[1]    [2]     [3]     [4]     [...]
 |       |        |        |
[0]    [1]      AP     PC
 PIX506

The APs would reside on one IP subnet (i.e. 10.0.0.x/24) while the LAN used another subnet (i.e. 192.168.1.x/24).  The APs & wireless clients would use the PIX506 "outside" interface as their default gateway, while the LAN gateway router would have a route to the 10.0.0.x/24 network pointed at the PIX506 "inside" interface.  As noted, it would be possible for a wireless host to attack the unmanaged switches with a MAC address flood, thereby circumventing the PIX, so this is not recommended.
0
 

Author Comment

by:comtekso
ID: 13578369
Thanks. I have a small network. I will have two Cisco Aironet AP's serving no more than 12 clients. Probably more likely to be 5 or 6 to start with. This is all for a new in-house  Electronic Medical Records System, so security has to be tight in order to meet all the different associations requirements for patient health information.

So if I am reading correctly if I use the PIX501 then I will not need a seperate switch for the AP's, right?

Would there be any performance benifits over the 506e or 501? The wireless clients will be using terminal services to connect to the new EMR system.

Note: I actually have a PIX506e that handles our T1 traffic, but it is provided by one of our vendors and I don't have access to configure it. I want to keep this seperate anyway.
0
 
LVL 10

Expert Comment

by:ruddg
ID: 13578432
The PIX501 would be suitable for your needs.  I would recommend buying it with the 50-user license.  And, yes, if you only have two APs, you can use the integrated ethernet hub on the PIX501 thereby eliminating the need for an additional switch.
0
 

Author Comment

by:comtekso
ID: 13578483
Thank you for the excellent information.
0
 
LVL 10

Expert Comment

by:ruddg
ID: 13578495
Note: the PIX501 supports 60Mbps of firewall throughput and 3Mbps 3DES / 4.5Mbps AES VPN throughput -- this is probably sufficient to handle your wireless networking needs.  The PIX506E provides up to 100Mbps firewall throughput and 16Mbps 3DES / 30Mbps AES VPN throughput.  If you are considering using VPN clients on your wireless clients to provide encryption (much better than WEP), the 506E may be a better fit.  However, the 506E does not have an integrated 4-port 10/100 switch like the PIX501 does.
0

Featured Post

Keep up with what's happening at Experts Exchange!

Sign up to receive Decoded, a new monthly digest with product updates, feature release info, continuing education opportunities, and more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Powerful tools can do wonders, but only in the right hands.  Nowhere is this more obvious than with the cloud.
This article explains the fundamentals of industrial networking which ultimately is the backbone network which is providing communications for process devices like robots and other not so interesting stuff.
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
When cloud platforms entered the scene, users and companies jumped on board to take advantage of the many benefits, like the ability to work and connect with company information from various locations. What many didn't foresee was the increased risk…
Suggested Courses

621 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question