Transparent mode on a PIX

Posted on 2008-11-11
Last Modified: 2012-05-05
How do I set up transparent mode on both the command line and PDM
Question by:johnc0817
    LVL 11

    Expert Comment

    Firstly, you can only run transparent mode in version 7. Hence, make sure that's what you are running

    In transparent mode the PIX does not have IP addresses assigned to its interfaces. Instead it acts as a Layer 2 bridge that maintains a MAC address table and makes forwarding decisions based on that. The use of full extended IP access lists is still available and the firewall can inspect IP activity at any layer. In this mode of operation the PIX is often referred to as a "bump in the wire" or "stealth firewall". There are other significant differences as to how transparent mode operates in comparison to routed mode:

        *      Only two interfaces are supportedinside and outside
        *      NAT is not supported or required since the PIX is no longer a hop

    Make sure you read this overview of the mode too here:

    To set up transparent mode on the firewall, either do firewall transparent or mode transparent from the configuration mode

    You can follow this example to create a configuration:


    Author Comment

    Can I set this up in PDM or must I use command line?
    LVL 11

    Accepted Solution

    I don't know what version of PDM you are running but all configuration docs are located here. check your 'show version' on the firewall and find out what PDM version you have. Then choose here

    There are some references to setting transparent mode at these links:

    Featured Post

    How to run any project with ease

    Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
    - Combine task lists, docs, spreadsheets, and chat in one
    - View and edit from mobile/offline
    - Cut down on emails

    Join & Write a Comment

    If you have an ASA5510 then this sort of thing would be better handled with a CSC Module, however on an ASA5505 thats not an option, and if you want to throw in a quick solution to stop your staff going to facebook during work time, then this is the…
    I recently updated from an old PIX platform to the new ASA platform.  While upgrading, I was tremendously confused about how the VPN and AnyConnect licensing works.  It turns out that the ASA has 3 different VPN licensing schemes. "site-to-site" …
    Migrating to Microsoft Office 365 is becoming increasingly popular for organizations both large and small. If you have made the leap to Microsoft’s cloud platform, you know that you will need to create a corporate email signature for your Office 365…
    Polish reports in Access so they look terrific. Take yourself to another level. Equations, Back Color, Alternate Back Color. Write easy VBA Code. Tighten space to use less pages. Launch report from a menu, considering criteria only when it is filled…

    754 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    19 Experts available now in Live!

    Get 1:1 Help Now