Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Configuring PIX Firewall

Posted on 2009-05-14
2
Medium Priority
?
266 Views
Last Modified: 2012-05-06
Hello

I am an IT administrator for Fully Microsoft based Network , Internet , Email and every thing work fine.

The next plan is to install PIX Firewall in front of ISA.

I am new to Cisco PIX , so I need full configuration to setup the PIX 506E. either using command line or PDM web Interface.

What I need excatly to do , is firstly allow Internet connection , secondaly , forward any SMTP Traffic to ISA Server because I am publishing the Exchange Server through ISA.

Internet Router === PIX=====ISA====LAN

Any Help

0
Comment
Question by:Hisham_Elkouha
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 7

Assisted Solution

by:Ilir Mitrushi
Ilir Mitrushi earned 300 total points
ID: 24382790
Depending on your pix software follow instructions from config guides you can find on cisco.com. Here is a link you can start with
http://cisco.com/en/US/products/sw/secursw/ps2120/products_installation_and_configuration_guides_list.html
0
 
LVL 7

Accepted Solution

by:
egyptco earned 1200 total points
ID: 24383035
there are a lot configuration examples you would find in web (e.g. http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a0080094768.shtml) but since you have already working infrastructure adding new firewall would result in changing your ip addressing scheme. i would recommend instead of pix to buy asa which is successor of the pix family and do transparent firewall. the firewall in this mode is like bump on the wire works as L2 device, which you can connect between your isa and isp router without renumbering and changing already existing L3 settings.

otherwise you need to:

1. if needed extend and divide your external ip range from your ISP in 2 subnes. leave the external ip address of the ISA (spending you whole bunch reconfiguration work) and connect it with the PIX. this makes your inside from pix prospective.
ISP ---(new.subnet)---PIX---- (old.subnet)----ISA

2. on asa configure default gateway being the inside ip of the PIX

3. configure default route on the PIX, next hop your ISP router

4. configure nat exeption rule on your inside. your ISA remains in charge  for nat:
nat (inside) 0 0.0.0.0 0.0.0.0

5. configure ACLs permitting whatever kind of traffic you allows inbound on your pix's outside interface. e.g. SMTP
access-list acl-outside permit tcp any host <ISA's ip address> eq 25
access-group acl-outside in interface outside

6. configure static nat translation to your ISA server. (PIX doesn't route if there is no xlate translation slot)
static (inside,outside) tcp interface 25 <ISA's ip address> netmask 255.255.255.255

7. do your tests if the whole thing works as suppose to.
0

Featured Post

What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

On Feb. 28, Amazon’s Simple Storage Service (S3) went down after an employee issued the wrong command during a debugging exercise. Among those affected were big names like Netflix, Spotify and Expedia.
This article is in regards to the Cisco QSFP-4SFP10G-CU1M cables, which are designed to uplink/downlink 40GB ports to 10GB SFP ports. I recently experienced this and found very little configuration documentation on how these are supposed to be confi…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

598 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question