Link to home
Create AccountLog in
Avatar of Rowdyone52
Rowdyone52

asked on

Cisco 2800 Series Router - Routing Internet & Private Line

I have a 2800 Series router and I will be using it to replace an older 2600 series router that does nothing but route a T1 to the Firewall.  The T1 connection is through a serial WIC/T1 card and the T1 is terminated through an Adtran unit.

I also have another 1600 series router that connects the LAN to a remote office via a private line connected to the router via a serial WIC/T1 Card.

Separately both of these connections are very easy to configure and route within the LAN.

My Question is this....
How can I combine both of the connections into the one external router, and guarantee that the Private line is secure from the internet line??
Avatar of calvinetter
calvinetter
Flag of United States of America image

Easy.  Just purchase the router with the "Advanced Security" feature set, & enable CBAC on the Internet interface (more advanced firewalling than plain old ACLs), to protect your internal subnets (local LAN or remote subnet via private T1) from external attacks or connection attempts.

   Configuring CBAC - IOS 12.4:
http://www.cisco.com/en/US/products/ps6350/products_configuration_guide_chapter09186a00804a41c5.html
   Some tips on securing routers:
http://www.cisco.com/en/US/tech/tk648/tk361/technologies_tech_note09186a0080120f48.shtml
   Bookmark the "Cisco Security Advisories" page, & check it often:
http://www.cisco.com/en/US/products/products_security_advisories_listing.html

cheers
Avatar of Rowdyone52
Rowdyone52

ASKER

There is no way to do it without the feature set?

For instance configure both Serial interfaces then route serial 0 (internet to E0) plugged into firewall and router serial 1 to E1 plugged into Lan?

Would the lan be open to the internet configuration?
ASKER CERTIFIED SOLUTION
Avatar of calvinetter
calvinetter
Flag of United States of America image

Link to home
membership
Create a free account to see this answer
Signing up is free and takes 30 seconds. No credit card required.
See answer