Solved

Network Design with excess equipment

Posted on 2006-07-17
8
462 Views
Last Modified: 2010-03-19
Currently I have the following set up:
 Router>Outside-Switch>Pix515E>Proxy>Inside-Switch>LAN—
                                              |
                                    [DMZ Switch]
                                              |
                                    [4215 IDS](Only have 2 interfaces in promiscuous mode)

I would like to use the excess network devices to redesign and add a better security posture.  I have another Pix515E, IDS, and a few more switches.  This is the design that I was considering.  Please give feedback on how I can use and configure these devices in our current topology.

Router>Outside-Switch>Pix>Inside-Switch
                                     |                |
                              [DMZ-Switch]   [Pix515E]
                                 |                       |
              [WEB-Server] [IDS 4215]    [IDS 4215]
                                                             |
                                                    [Inside-Switch]
                                                               |
                                                            [LAN]
0
Comment
Question by:Jelonet
8 Comments
 
LVL 14

Assisted Solution

by:Juan Ocasio
Juan Ocasio earned 50 total points
ID: 17126471
The set up looks fine just one question:  Why do you have the Inside-Switch between the Pix (what model) and Pix515E?
0
 
LVL 12

Expert Comment

by:r_naren22atyahoo
ID: 17126781
Router>Outside-Switch>Pix>Inside-Switch
                                     |                |
                              [DMZ-Switch]   [Pix515E]
                                 |                       |
              [WEB-Server] [IDS 4215]    [IDS 4215]
                                                             |
                                                    [Inside-Switch]
                                                               |
                                                            [LAN]

You would have problem with the traffice is passing via 2 PIXs
You have come accross the Double NATing and GRE protocols dont work well with Double NATting

And also you have to maintain 2 identical set of rules for inside network on 2 PIXs as the traffice is passing these 2 PIXs

regards
naren
0
 
LVL 12

Accepted Solution

by:
r_naren22atyahoo earned 200 total points
ID: 17126799
I would Do some thing like this

                     Public(internet)
                             |
                           PIX_1    
                             |               }  This will be the DMZ network,Is this DMZ having Public IP address or a Private IP address
                             |               } If the DMZ has Public do the NAT on the PIX_2 else do the NAT on PIX_1
                           PIX_2
                            |
                            |
                         LAN
0
 
LVL 22

Expert Comment

by:Rick Hobbs
ID: 17126919
Are the PIX515Es part of a failover bundle?  If yes I would:
                                   |Pix515E secondary|
Router>Outside-Switch>|Pix5i5E     primary|>Inside-Switch
                                     |                   |
                              [DMZ-Switch]       Proxy
                                 |                       |
              [WEB-Server] [IDS 4215]    [IDS 4215]
                                                             |
                                                    [Inside-Switch]
                                                               |
                                                            [LAN]
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 79

Assisted Solution

by:lrmoore
lrmoore earned 200 total points
ID: 17127325
Just some comments on placing IDS outside the pix:
If everyone on the planet is knocking on the door to see what's available, then putting IDS on the outside of the PIX will bury you in looking at people that are knocking. Who cares when we all know every freak on planet earth is knocking? You time is much better spent elsewhere.
All I want to know is what is happening *inside* my network
If you don't have the 2 PIX's in failover mode, then this could be one way to add resiliency, but not *security*
You can't address *security* by doubing what you have. You address security by adding layers of defense - host based IDS, clean access, AV, inline URL filtering, written policies, user education, etc, etc..
0
 
LVL 44

Assisted Solution

by:scrathcyboy
scrathcyboy earned 50 total points
ID: 17127903
USe the excess equipment on other networks.  One switch or router PER class C network is all you want and need, they all do stealth firewalling, so you are just giving yourself unneeded headaches by using more than one switch or router per network.
0
 

Author Comment

by:Jelonet
ID: 17128938
The Pix are unrestricted.  I have seperate Pix for failover.  The inside switch is a 3650.  The DMZ addresses are public addresses.
0
 
LVL 12

Expert Comment

by:r_naren22atyahoo
ID: 17135007
Thanks, if both are 515s, use ASDM with PIX 7.1 or 7.2 , management will be easy for you!
0

Featured Post

Control application downtime with dependency maps

Visualize the interdependencies between application components better with Applications Manager's automated application discovery and dependency mapping feature. Resolve performance issues faster by quickly isolating problematic components.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you're not part of the solution, you're part of the problem.   Tips on how to secure IoT devices, even the dumbest ones, so they can't be used as part of a DDoS botnet.  Use PRTG Network Monitor as one of the building blocks, to detect unusual…
PRTG Network Monitor lets you monitor your bandwidth usage, so you know who is using up your bandwidth, and what they're using it for.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

920 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now