cisco pix 515e

I need to know if my pix will support 2 ISPs, meaning if the primary ISP goes down the backup would take over, can this be done?
LVL 1
tstuardoAsked:
Who is Participating?
 
nodiscoCommented:
Hi there

not specifically with a pix.  Outbound traffic to the internet goes out the outside interface on a pix and this interface cannot terminate an internet connection - let alone 2 of them.  You can of course have 2 ISPs and a PIX inside, but the edge routers are what do the work.  ie.

  ISP 1                             ISP 2
Edge router 1               Edge router 2
         Both sharing 1 ethernet address
                          +
                         PIX

Have BGP between both routers and you have full failover for ISPs

A simpler solution would be one edge router with 2 interfaces - one for each ISP.  In the event of one going down, you have the second connection to provide internet connectivity - as I said - a few ways of doing this.  But the pix does not care or know whether the ISPs circuit has gone down or not.  It has an ethernet connection to the edge router(s) and if the ISP link goes down, the pix won't know as the ethernet interface is still up.

heop this helps
0
 
lrmooreCommented:
Not with PIX by itself. I can only support one default gateway at a time.
However, it really depends on your connections to the ISP(s).
If you have, say, a T1 from ISPA and a T1 from ISPB, then I would assume you also have T1 Routers:

   ISPA               ISPB
     T1                  T1
   Router1          Router2
        |_ _ _______|
                 |
           PIX Outside

With this scenario, you have several choices. You can use dynamic routing protocols such as OSPF so that both routers and the PIX talk to each other and they all 3 know which T1 is up/available. Your dilema here will be which ISP's public IP address space are you using on the PIX outside? You can't use both, so perhaps Router2 does a double-nat . . .

If you have DSL or other ISP connections, or T1 and DSL then you have other problems that are not easy to overcome.   Can you better explain your external connections to your 2 ISP's ?

There are many dual-WAN capable firewalls on the market. The PIX is not one of them.
Linksys RV0x2 series
Linksys RV082:
http://www.linksys.com/products/product.asp?prid=589&scid=29

Fortinet:
http://www.fortinet.com/products/telesoho.html

Netgear FVS318
http://www.netgear.com/products/prod_details.php?prodID=129&view=

Zyxel Zywall
http://www.zyxel.com/product/model.php?indexcate=1073271397&indexFlagvalue=1021873683

hot Brick - dual WAN
http://www.hotbrick.com/lb-2.html

Watchguard Firebox
http://www.watchguard.com/products/

Xincom
http://www.xincom.com/products.html

RadWare
http://www.radware.com/content/products/lpb/default.asp
0
 
lrmooreCommented:
LOL! Great minds think alike!
0
 
nodiscoCommented:
:-)
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.