Link to home
Start Free TrialLog in
Avatar of Traction IT
Traction ITFlag for Netherlands

asked on

Your opinion about connecting 3 Cisco PIX 506e firewalls?

I would like your opinion about connecting 3 Cisco PIX 506e firewalls. I have 3 offices which I would like to connect to eachother. This must be done by creating VPN's. The connections between the offcies are made by direct fiber connections (LAN-to-LAN, no routing, no internet access). Is it needed or recommended to use routers between those connections in front of the PIX firewalls. OR it is possible to give the 3 firewalls IP-addresses like 10.10.10.1  .2 and  .3, creating internal ranges at the 3 offices and use static routes. Is that possible? What do you recommend for this scenario?
Avatar of RPPreacher
RPPreacher
Flag of United States of America image

Static routes are fine.
Avatar of Traction IT

ASKER

in fact the Cisco PIX is also a basic router isn't it? What do you think, Cisco PIX 506E or a Cisco 870 series router?
A PIX can do basic routing.  It is not a router.

Use a PIX if you need firewall services or VPN tunnels, otherwise a 870 will be fine.
Indeed, I need VPN tunnels and good, reliable security... PIX for me?
You need to place the pix 's at your perimeter and try making  a vpn mesh for redundancy.
Pix can do static routing. configure site-to-site vpns on the pixes.

Renill
Anything else you need before closing this question?
Yes... I'm talking about LAN-LAN connections which are already VLAN'ed by the provider, we are talking about a private LAN-LAN connection without internet access. Maybe it's better than to make use of simple routers and not a firewall, like the PIX.

If it is a private l2l connection, VPN is unnecessary.  You may want to firewall if you are worried about isolating traffic from place to place.

I think the router (since no VPN) would be best.
i'd also look at an ASA vs a PIX - the ASA provides traffic management capabilities also.  you can always plug a modem / router into the Appliance later if needed for vpn etc.

the PIX would also provide a higher level of security.
When I just want to "connect" the locations by using static routes and no other special things, what do you all advice me to use for type of router?
how many users per site?>  what type of traffic is being passed?

you could enable ripV2 so the router can learn about the routes, - vs static entries.  


In fact only RDP-traffic, some print traffic and somewhat internet traffic, it's about 4 sites.

main site  (here are the servers located) (4 Mb LAN-LAN connection)
sub site  max. 10 users  (2 Mb LAN-LAN connection)
sub site  max. 10 users  (2 Mb LAN-LAN connection)  
sub site  max. 15 users  (2 Mb LAN-LAN connection)  

At the main site there already is an internet connection which have it's own seperate firewall for internet access.
ASKER CERTIFIED SOLUTION
Avatar of RPPreacher
RPPreacher
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
what is websense? an additional product for an cisco 800? or an additional device?
www.websense.com  its a software add on for the router / firewalls.