Link to home
Start Free TrialLog in
Avatar of jbisordi
jbisordi

asked on

Cisco PIX 501: Can I place the outside/inside on the same subnet?

Hello All!

I am a complete routing/firewall/Cisco newbie so please bear with me and forgive my lack of knowledge as you read my question! It's in two parts: the "is this possible" part and the "how do I accomplish it" part.

I have a 192.168.1.X/24 network with a gateway of 192.168.1.1. I want to take 10 computers and restrict their access to the network (only allowing HTTP in and out to the gateway). Is it possible to place these 10 PC's behind the PIX 501 and accomplish this? Difficulty: I must keep the IP and subnet of the 10 PC's the same as the rest of the network.

If so, how would I do this? I have already set the IP of my outside and inside interface, created the HTTP rule and disabled DHCP. Now what do I do? Define static routes or something? I'm in over my head at this point in the config.

Thanks for any help you can offer!

Mike
ASKER CERTIFIED SOLUTION
Avatar of fm250
fm250
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
here is an example where it allows only port 80, but rarly some webservers use different ports than 80
https://www.experts-exchange.com/questions/21726934/PIX-501-restricting-access-to-port-80.html
Avatar of jbisordi
jbisordi

ASKER

fm250,

Basically I want to place 10 PC's behind the firewall, only allowing http in and out, only allowing outbound traffic to the gateway (192.168.1.1), and keeping both the inside and outside IP range and subnet the same...

Mike
BTW, if you are securing the network as you mention in the other question then you should have all of your PCs inside the network, then define access lists
did you look to the example above, also your other question should be just a pointer to this one, so you can track the comments.