PIX 515E Firewall Setup

Posted on 2006-05-28
Last Modified: 2013-11-16
I am seeking for professional support in improving my existing network security levels and maximizing the business continuity by minimizing the risk in LAN & WAN.

I have 3 interfaces - inside -, outside - and DMZ My exchange server, proxy server and web server - (,  should be connected to “inside” interface and in “DMZ” – ( I am planning to implement Trend  Micro SMTP gateway which could pull all SMTP traffic which is forwarding by my ISP, my ISP is mail forwarding to address. My“outside” interface is connected to VSAT modem (Gateway - And from my exchange side all outgoing SMTP traffic is forwarded to ISP DNS address (

In addition all my proxy traffic must route through my ISA server which is in “inside” interface. I have plans to enable outlook web access in a additional front-end server; do you recommend this if it yes where should I keep the server in DMZ or Inside?

Question by:virajw2310
    1 Comment
    LVL 10

    Accepted Solution

    One possible Recomendation could be to:

    VSAT Gateway Modem:

    ISA Server
    Proxy Server
    Web Server
    Outlook Web Access Front End Server

    Exchange Server
    All Internal Clients

    On your PIX, you will allow Internal Clients to access DMZ for Proxy and Web Server

    Configure the Outlook Web Access Frond End server to read mailbox information from Exchange Server. You can also create a static NAT entry to forward all incomming traffic from your ISP directly into OWA Frond End server and configure it to forward it to your internal Exchange Server. Mailboxes should will reside in internal Exchange Server. OWA server will need to have access to AD for Client Authentication.

    Create Static NATs for your Webserver on PIX if it needs to be accessed from the Internet, if not, you can move it to your inside Network.

    Again, this is only recomendation, your Business requirements may or may not work with it. You may also look into hiring a third partry Network Security Company to design it for you.

    Featured Post

    How to run any project with ease

    Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
    - Combine task lists, docs, spreadsheets, and chat in one
    - View and edit from mobile/offline
    - Cut down on emails

    Join & Write a Comment

    If your business is like most, chances are you still need to maintain a fax infrastructure for your staff. It’s hard to believe that a communication technology that was thriving in the mid-80s could still be an essential part of your team’s modern I…
    Data center, now-a-days, is referred as the home of all the advanced technologies. In-fact, most of the businesses are now establishing their entire organizational structure around the IT capabilities.
    After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
    This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor ( If you're looking for how to monitor bandwidth using netflow or packet s…

    734 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    20 Experts available now in Live!

    Get 1:1 Help Now