Solved

Configuring PIX Firewall

Posted on 2009-05-14
2
261 Views
Last Modified: 2012-05-06
Hello

I am an IT administrator for Fully Microsoft based Network , Internet , Email and every thing work fine.

The next plan is to install PIX Firewall in front of ISA.

I am new to Cisco PIX , so I need full configuration to setup the PIX 506E. either using command line or PDM web Interface.

What I need excatly to do , is firstly allow Internet connection , secondaly , forward any SMTP Traffic to ISA Server because I am publishing the Exchange Server through ISA.

Internet Router === PIX=====ISA====LAN

Any Help

0
Comment
Question by:Hisham_Elkouha
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 7

Assisted Solution

by:Ilir Mitrushi
Ilir Mitrushi earned 100 total points
ID: 24382790
Depending on your pix software follow instructions from config guides you can find on cisco.com. Here is a link you can start with
http://cisco.com/en/US/products/sw/secursw/ps2120/products_installation_and_configuration_guides_list.html
0
 
LVL 7

Accepted Solution

by:
egyptco earned 400 total points
ID: 24383035
there are a lot configuration examples you would find in web (e.g. http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a0080094768.shtml) but since you have already working infrastructure adding new firewall would result in changing your ip addressing scheme. i would recommend instead of pix to buy asa which is successor of the pix family and do transparent firewall. the firewall in this mode is like bump on the wire works as L2 device, which you can connect between your isa and isp router without renumbering and changing already existing L3 settings.

otherwise you need to:

1. if needed extend and divide your external ip range from your ISP in 2 subnes. leave the external ip address of the ISA (spending you whole bunch reconfiguration work) and connect it with the PIX. this makes your inside from pix prospective.
ISP ---(new.subnet)---PIX---- (old.subnet)----ISA

2. on asa configure default gateway being the inside ip of the PIX

3. configure default route on the PIX, next hop your ISP router

4. configure nat exeption rule on your inside. your ISA remains in charge  for nat:
nat (inside) 0 0.0.0.0 0.0.0.0

5. configure ACLs permitting whatever kind of traffic you allows inbound on your pix's outside interface. e.g. SMTP
access-list acl-outside permit tcp any host <ISA's ip address> eq 25
access-group acl-outside in interface outside

6. configure static nat translation to your ISA server. (PIX doesn't route if there is no xlate translation slot)
static (inside,outside) tcp interface 25 <ISA's ip address> netmask 255.255.255.255

7. do your tests if the whole thing works as suppose to.
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Overview The Cisco PIX 501, PIX 506e, ASA 5505 and ASA 5510 (most if not all of this information will be relevant to the PIX 515e but I do not have a working configuration handy to verify the validity) are primarily used within small to medium busi…
From Cisco ASA version 8.3, the Network Address Translation (NAT) configuration has been completely redesigned and it may be helpful to have the syntax configuration for both at a glance. You may as well want to read official Cisco published AS…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

739 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question