Create DMZ with PIX 501

Posted on 2007-11-21
Last Modified: 2008-02-01
I am trying to create a DMZ zone with PIX 501 firewall and a netgear switch. I have Verizon FIOS with one public IP address. The outside interface of the firewall is connected to FIOS demarc and the inside interface has a LAN address rabge of 192.168.1.x
ip address outside
ip address inside
The Netgear switch (acctually it a wireless router but im only using as a switch) is connected to the firewall inside LAN port. The netgear IP range is 10.10.111.x What i would like to do is have a web server on the Netgear (DMZ) switch with an IP address of
Question by:Mikeyb19ave
  • 2
  • 2
LVL 25

Expert Comment

ID: 20340888
First of all, I am extremely jealous of you that you have Verizon's FIOS available to you.

Second, as I'm sure you know the PIX 501 will only support one subnet on each interface.  If you don't need to use the wireless portion on the router, I'd turn it off, if you can.  Plug the wan port into the same subnet as the PIX inside interface, then move the web server to the switch (or inside of the netgear router) side.  Give the router a static IP.  Then forward the ports on the PIX to the router ip that for port 80/443.  Do the mapping on the netgear as well.  The only other option I can think of is swap the hosts around.  Put the web server in between teh pix and the router so you don't double NAT the static mapping, but double-NAT the clients.  If that works, then you can still use the wireless ability of the router if you wish.

I can't guarantee this will work as there is essentially a double-NAT happening here and I've never done that before.  However logically speaking that should.  If not, then you should either swap your 501 out for an ASA 5505 (can assign different ports to a different VLAN, then just need a second switch).  The 5505 route is the way I'd go personally.

Author Comment

ID: 20361856
I have set this up just as you suggested... To test I have attached a laptop to the Netgear subnet... I am able to browse the internet and also able to ping host ip address's on the Pix subnet (192.168.1.x)...I am also able to ping the outside interface of the Netgear Roiuter ( from the Pix Subnet... I am unable to ping or telnet via the port i opened for test (375) the inside subnet of the Netgear router (10.10.111.x)..  
LVL 25

Accepted Solution

Cyclops3590 earned 250 total points
ID: 20362423
first, I just want to verify which way you set up

Internet <--pix--> <--netgear-->

also when you say "unable to ping or telnet via port i opened for test...", where are you pinging to.  You should be able to ping from the to the 192 network.  You most likely won't be able to ping from the 192 to 10 network.  However if you telnet to the port that is mapped, it should work.

However if you have your client behind the netgear, I would put the server on the 192 network and your clients behind the netgear

Author Comment

ID: 20362545
ok... i see what your saying... it does work when the clients are behind the netgear... Thanks for help

Featured Post

Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Cisco Supervisor upgrade to 2T 3 47
Upgrading Cisco 1142N lightweight wireless access point 2 40
CCNA Data center exam questions 8 80
traffic flow without STP 9 45
How to configure Site to Site VPN on a Cisco ASA.     (version: 1.1 - updated August 6, 2009) Index          [Preface]   1.    [Introduction]   2.    [The situation]   3.    [Getting started]   4.    [Interesting traffic]   5.    [NAT0]   6.…
Overview The Cisco PIX 501, PIX 506e, ASA 5505 and ASA 5510 (most if not all of this information will be relevant to the PIX 515e but I do not have a working configuration handy to verify the validity) are primarily used within small to medium busi…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

912 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now