Solved

Adding Additional Ethernet Ports On A Cisco Pix 501

Posted on 2008-10-03
7
534 Views
Last Modified: 2010-04-21
Hello,

This may seem like a basic question.  I have used up the 4 ethernet ports on my existing Pix 501 and need to add up to 4 more machines.  

What is the best approach in adding the additional ports?  Can I connect a switch?  Can I link another Pix to the existing one?  

Each machine uses NAT rules to make them accessible as web servers....if that will make a difference in the suggestion.  Thanks in advance for your help.
0
Comment
Question by:craigbtg
7 Comments
 
LVL 3

Expert Comment

by:JJLost
ID: 22638016
The answer depends on your needs for future scalability but from what I read it sounds like you could satisfy your needs if you just daisy chain a switch
0
 
LVL 12

Expert Comment

by:Pugglewuggle
ID: 22638133
The best thing to do is get a switch. An inexpensive unmanaged one will be fine since the PIX's inside interface is an unmanaged switch as well.
Just plug one port of the PIX's inside interface into one port of the switch and you'll be good to go.
The size of the switch depends on your requirments. I highly recommend Linksys's Business Series unmanaged switches. They have a lifetime warranty and you can get them in several configurations to match your requirements!
If you get the get the SD2008, that has 8 ports on it - you'll use one for your connection to the PIX and then you'll have 7 ports left over for PCs and other devices. One very cool thing - this is a gigabit switch so if any of your PCs have gigabit NICs they'll be able to communicate at gigabit speeds when connected through the switch even though the PIX is only 10/100.
Here's a link to Linksys's unmanaged Business Series switches.
http://www.linksys.com/servlet/Satellite?c=L_Product_C1&childpagename=US%2FLayout&cid=1134691194560&pagename=Linksys%2FCommon%2FVisitorWrapper&lid=9456061982B03 
Cheers! Let me know if you have any questions!
0
 
LVL 12

Expert Comment

by:Pugglewuggle
ID: 22638140
BTW - the PIX handles all NAT and access filtering - the switch just extends your network.
Cheers!
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 5

Expert Comment

by:devangshroff
ID: 22639742
HI,

  Do nating on ASA and connect a 8 pr 24 port switch in e0/1 that is inside interface ,
this wway u can expand your network.

there aare basic six command u need to do on ASA to start your internet
Punlic ip address on outside intefae e0/0
nameif outside
Private ip address in inside intefase e0/1
nameif inside
nat (inside) 1 0 0
global (outside) 1 inteface
route outside 0 0 remote ip address
and one access list to allow trafic.

done
0
 
LVL 12

Expert Comment

by:Pugglewuggle
ID: 22639896
It doesn't matter which port he connects the switch to on a PIX 501 as long as it's on the inside interface and that interface isn't shutdown. All of the ports operate logically as one in the device. That's why a PIX 501 config only has 2 interfaces - inside and outside.
The asker said "Each machine uses NAT rules to make them accessible as web servers" which tells me that he already has NAT setup, so there is no need to re-run the NAT commands.
BTW to craigbtg: Regarding the effect that expanding the network with a switch will have when NAT is used, it will have none as long as you use an unmanaged switch (or a managed one with all the ports on the default VLAN). Like I said though, I recommend the Linksys SD2008 because you said you need 4 more PCs on the inside... that will give you 3 leftover ports after those 4 PCs and the uplink to the PIX. Also, the PCs attached to the switch can communicate between eachother at gigabit speeds.
Cheers!
0
 
LVL 12

Accepted Solution

by:
Pugglewuggle earned 500 total points
ID: 22639898
BTW - the SD2008 is only about $60 USD! A great deal too!
0
 

Author Closing Comment

by:craigbtg
ID: 31502920
Great, thank you very much for your help.  I was hoping there was an inexpensive option.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Palo Alto Networks FW: Can you view bw utilization of specific tunnels? 2 67
Setting up a VPN 60 141
VIRTUAL NETWORKING 3 62
Setup another VLAN on Fortigate 3 24
Optimal Xbox 360 connectivity requires "OPEN NAT". If you use Juniper Netscreen or SSG firewall products in a home setting, the following steps will allow you get rid of the dreaded warning screen below and achieve the best online gaming environment…
I found an issue or “bug” in the SonicOS platform (the firmware controlling SonicWALL security appliances) that has to do with renaming Default Service Objects, which then causes a portion of the system to become uncontrollable and unstable. BACK…
This Micro Tutorial will give you a basic overview how to record your screen with Microsoft Expression Encoder. This program is still free and open for the public to download. This will be demonstrated using Microsoft Expression Encoder 4.
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

809 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question