Solved

Connect two PIX firewalls

Posted on 2006-06-17
9
283 Views
Last Modified: 2013-11-16
I have two networks in the same building.
Network one is on a ip 10.64.1.0 and network two is on 10.247.1.0
I have a PIX 515 on the 10.64 net and a PIX 520 on the 10.247 net.
I am trying to connect to a exchange server at 10.247.121.1.5 from
the 10.64.1.0 network.  I have attempted to bridge the network via
server 2003.  The exchange server is also 2003.  I can ping inside
on the 10.64.1.0 net to the 10.64.1.23 ip of the bridge.  Outside
the city, I have several sites throughout the state, which cannot ping.
My current plan is to attempt to connect the two pix's together
(they are in the same server room) with a second interface in each
via a cross over cable.

Can anyone provide me with what my config should look like?
The pix's are running 4x software.
0
Comment
Question by:Heath Calhoun
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 4
9 Comments
 
LVL 32

Expert Comment

by:rsivanandan
ID: 16928467
4x ? I would first suggest you to upgrade it to 6.3(5) because your configuration is going to involve a lot of nat exclusions and stuff like that. The most stable version is 6.3(5).

Cheers,
Rajesh
0
 
LVL 11

Expert Comment

by:prueconsulting
ID: 16929736
And how are the Pix's configured in the way of

Outside Interface / Inside etc.. Can you provide a small context diagram
0
 

Author Comment

by:Heath Calhoun
ID: 16931007
No smartnet, so unfortunately we can't upgrade.
The last time I tried to upgrade to 5x, after leaving, we had to return to downgrade back to ver 4.  5x stopped the firewall from working.
Also, I have a bunch of conduits setup to work.  Unless they have changed, I don't like the fact that the firewall stops checking for matches
after it finds the first match in a access list.
0
Space-Age Communications Transitions to DevOps

ViaSat, a global provider of satellite and wireless communications, securely connects businesses, governments, and organizations to the Internet. Learn how ViaSat’s Network Solutions Engineer, drove the transition from a traditional network support to a DevOps-centric model.

 

Author Comment

by:Heath Calhoun
ID: 16931035
Maybe this helps.
Pix 10.64 resides on a state dps network going through a dps firwall to get to the outside.
Pix 10.247 resides on the state its network to get out.
Both pix's are in the same computer room.

The 10.247.121.x pix route:
outside 0.0.0.0 0.0.0.0 10.247.126.1 1 OTHEr static
inside 10.247.121.0 255.255.255.0 1 CONNECT static
outside 10.247.0 255.255.255.248 10.247.126.2 1 CONNECT static

The 10.64.163.x pix
outside 0.0.0.0 0.0.0.0 10.64.164.1 1 OTHER static
inside 10.64.163.0 255.255.255.0 10.64.163.1 1 CONNECT static
outside 10.64.164.0 255.255.255.0 10.64.164.2 1 CONNECT static

Both firwalls connect ultimately to the state network and then to the internet.
The 10.64 pix goes through the dps network as well to get through their firewall
to the its network.  The 10.247 pix goes to the its network.
Both firewalls are in the same computer room and need to be tied together with
network cards via a crossover cable.

its network to its firewall, internet
dps network, to dps firewall
router, pix 10.64, switch.

its network to itsfirwall, internet
router, pix 10.247. switch
0
 
LVL 11

Expert Comment

by:prueconsulting
ID: 16944775
Build a DMZ network in each on the same subnet .

Ie Pix 1 - 10.10.10.1
Pix 2 - 10.10.10.2

Point the Route on PIX 2 to put 10.247.121.0 through 10.10.10.1
PIX 1 - route 10.64.163.0 via 10.10.10.2

and then build approriate Acls to allow the traffic required.



0
 

Author Comment

by:Heath Calhoun
ID: 16948075
That would keep traffic seperate.
Will I need a static command and then a route?
Can you give me a config?  I've never built a dmz or route on a pix before.
Thanks.
0
 
LVL 11

Accepted Solution

by:
prueconsulting earned 125 total points
ID: 16948274
The DMZ is just build using one of the other interfaces installed on the PIX.
You shouldnt require a static at all .
ie

interface ethernet2 100full                                                    
nameif ethernet2 DMZ security50
ip address DMZ 10.10.10.1 255.255.255.0

   
example route commands are as follows

route DMZ 10.247.121.0 255.255.255.0 10.10.10.2 1
route DMZ 10.64.163.0 255.255.255.0 10.10.10.1 1
0
 

Author Comment

by:Heath Calhoun
ID: 16980867
Thanks prueconsulting.  That is basically what we did, except we used static.
0
 
LVL 11

Expert Comment

by:prueconsulting
ID: 16982706
Glad to be of assistance
0

Featured Post

Surfing Is Meant To Be Done Outdoors

Featuring its rugged IP67 compliant exterior and delivering broad, fast, and reliable Wi-Fi coverage, the AP322 is the ideal solution for the outdoors. Manage this AP with either a Firebox as a gateway controller, or with the Wi-Fi Cloud for an expanded set of management features

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Anyconnect landing page login failed 2 33
Resource timeout across a VPN 9 31
Blocking outside IP Addresses 16 59
Cisco ASA 5510 Question 3 11
Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
When speed and performance are vital to revenue, companies must have complete confidence in their cloud environment.
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

730 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question