How to configure a Cisco 2600 Router as a Pix Firewall

I let my Cisco certification expire 7 years ago because I had not worked with anything Cisco since I was in school.
During that schooling I was offered a certain Cisco security class which the instructor claimed would show how to configure a 2600 router as a Pix Firewall.  I skipped that class, and cannot seem to find anything related on the web.  
Is it possible to configure this way & if so is there simply a configuration file that I can upload to do it?
LVL 10
jasfoutAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

stsonlineCommented:
You can use access-lists and NATs to approximate some of the behavior of a PIX firewall, but the process is tedious and not intuitive at all. With the price of a base ASA 5505 at $350.00 USD (for a 10-user Base version) it's not really worth it.

However, if you want to try it, here are a few links (no, there isn't a basic config you can just put on a router):

http://www.cisco.com/en/US/docs/ios/11_3/security/configuration/guide/scacls.html
http://www.cisco.com/en/US/tech/tk648/tk361/technologies_tech_note09186a0080094e77.shtml

Configuration Examples:
http://www.cisco.com/en/US/products/sw/secursw/ps1018/prod_configuration_examples_list.html



Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Vito_CorleoneCommented:
You will not be able to get a router to act exactly like a firewall. He was probably talking about CBAC, which is the IOS Firewall. Here's a configuration example:

http://www.cisco.com/en/US/products/sw/secursw/ps1018/products_tech_note09186a0080094e8b.shtml

Basically you have an ACL from the outside in, which blocks most things. You then use CBAC with "ip inspect" commands to look at the traffic going out and open up temporary holes in the ACL to allow the traffic back in from outside.
jasfoutAuthor Commented:
Thank you for the quick response!
Identify and Prevent Potential Cyber-threats

Become the white hat who helps safeguard our interconnected world. Transform your career future by earning your MS in Cybersecurity. WGU’s MSCSIA degree program was designed in collaboration with national intelligence organizations and IT industry leaders.

that1guy15Commented:
You are looking for the Cisco IOS firewall feature set. Here is a link that goes in to the details of IOS firewall.
http://www.calstatela.edu/faculty/egean/cs580/cisco-documents/Cisco-IOS-Firewall-Feature-Set.pdf 
Basically you need an IOS image that supports the IOS firewall feature set. You then can configure ACLs and inspection rules as you would a normal firewall. You also have the option of IDS/IPS functionality on some models.
 If you have a newer version of IOS on your 2600 that does support IOS firewall the best way to go about setting it up would be to use the cisco GUI (called SDM).
 
Hope this helps.
 
that1guy15Commented:
quick on the gun to accept an answer huh?
OH well :)
Vito_CorleoneCommented:
I thought the same thing, lol. Didn't even get the assist.
jasfoutAuthor Commented:
My apologies...I didnt realize Cisco was such a hot topic here.
When I accepted, there was only one comment, and it confirmed my suspicions.
You both provided valuable information and I may use it should I decide to configure that way.  For that I can only give you my thanks now....7 & 9 minutes quicker would have made the assist points for sure though.
:)
I will try not to be so quick on the gun in the future

It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Routers

From novice to tech pro — start learning today.