Improve company productivity with a Business Account.Sign Up

x
?
Solved

Network Design with excess equipment

Posted on 2006-07-17
8
Medium Priority
?
474 Views
Last Modified: 2010-03-19
Currently I have the following set up:
 Router>Outside-Switch>Pix515E>Proxy>Inside-Switch>LAN—
                                              |
                                    [DMZ Switch]
                                              |
                                    [4215 IDS](Only have 2 interfaces in promiscuous mode)

I would like to use the excess network devices to redesign and add a better security posture.  I have another Pix515E, IDS, and a few more switches.  This is the design that I was considering.  Please give feedback on how I can use and configure these devices in our current topology.

Router>Outside-Switch>Pix>Inside-Switch
                                     |                |
                              [DMZ-Switch]   [Pix515E]
                                 |                       |
              [WEB-Server] [IDS 4215]    [IDS 4215]
                                                             |
                                                    [Inside-Switch]
                                                               |
                                                            [LAN]
0
Comment
Question by:Jelonet
8 Comments
 
LVL 15

Assisted Solution

by:Juan Ocasio
Juan Ocasio earned 200 total points
ID: 17126471
The set up looks fine just one question:  Why do you have the Inside-Switch between the Pix (what model) and Pix515E?
0
 
LVL 12

Expert Comment

by:r_naren22atyahoo
ID: 17126781
Router>Outside-Switch>Pix>Inside-Switch
                                     |                |
                              [DMZ-Switch]   [Pix515E]
                                 |                       |
              [WEB-Server] [IDS 4215]    [IDS 4215]
                                                             |
                                                    [Inside-Switch]
                                                               |
                                                            [LAN]

You would have problem with the traffice is passing via 2 PIXs
You have come accross the Double NATing and GRE protocols dont work well with Double NATting

And also you have to maintain 2 identical set of rules for inside network on 2 PIXs as the traffice is passing these 2 PIXs

regards
naren
0
 
LVL 12

Accepted Solution

by:
r_naren22atyahoo earned 800 total points
ID: 17126799
I would Do some thing like this

                     Public(internet)
                             |
                           PIX_1    
                             |               }  This will be the DMZ network,Is this DMZ having Public IP address or a Private IP address
                             |               } If the DMZ has Public do the NAT on the PIX_2 else do the NAT on PIX_1
                           PIX_2
                            |
                            |
                         LAN
0
What Kind of Coding Program is Right for You?

There are many ways to learn to code these days. From coding bootcamps like Flatiron School to online courses to totally free beginner resources. The best way to learn to code depends on many factors, but the most important one is you. See what course is best for you.

 
LVL 22

Expert Comment

by:Rick Hobbs
ID: 17126919
Are the PIX515Es part of a failover bundle?  If yes I would:
                                   |Pix515E secondary|
Router>Outside-Switch>|Pix5i5E     primary|>Inside-Switch
                                     |                   |
                              [DMZ-Switch]       Proxy
                                 |                       |
              [WEB-Server] [IDS 4215]    [IDS 4215]
                                                             |
                                                    [Inside-Switch]
                                                               |
                                                            [LAN]
0
 
LVL 79

Assisted Solution

by:lrmoore
lrmoore earned 800 total points
ID: 17127325
Just some comments on placing IDS outside the pix:
If everyone on the planet is knocking on the door to see what's available, then putting IDS on the outside of the PIX will bury you in looking at people that are knocking. Who cares when we all know every freak on planet earth is knocking? You time is much better spent elsewhere.
All I want to know is what is happening *inside* my network
If you don't have the 2 PIX's in failover mode, then this could be one way to add resiliency, but not *security*
You can't address *security* by doubing what you have. You address security by adding layers of defense - host based IDS, clean access, AV, inline URL filtering, written policies, user education, etc, etc..
0
 
LVL 44

Assisted Solution

by:scrathcyboy
scrathcyboy earned 200 total points
ID: 17127903
USe the excess equipment on other networks.  One switch or router PER class C network is all you want and need, they all do stealth firewalling, so you are just giving yourself unneeded headaches by using more than one switch or router per network.
0
 

Author Comment

by:Jelonet
ID: 17128938
The Pix are unrestricted.  I have seperate Pix for failover.  The inside switch is a 3650.  The DMZ addresses are public addresses.
0
 
LVL 12

Expert Comment

by:r_naren22atyahoo
ID: 17135007
Thanks, if both are 515s, use ASDM with PIX 7.1 or 7.2 , management will be easy for you!
0

Featured Post

Improve Your Query Performance Tuning

In this FREE six-day email course, you'll learn from Janis Griffin, Database Performance Evangelist. She'll teach 12 steps that you can use to optimize your queries as much as possible and see measurable results in your work. Get started today!

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Originally, this post was published on Monitis Blog, you can check it here . It goes without saying that technology has transformed society and the very nature of how we live, work, and communicate in ways that would’ve been incomprehensible 5 ye…
This article explains the fundamentals of industrial networking which ultimately is the backbone network which is providing communications for process devices like robots and other not so interesting stuff.
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…
Monitoring a network: why having a policy is the best policy? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the enormous benefits of having a policy-based approach when monitoring medium and large networks. Software utilized in this v…

607 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question