?
Solved

PIX

Posted on 2010-03-31
8
Medium Priority
?
514 Views
Last Modified: 2012-05-09
I have aPIX 515 firewall.  I try to configure subinterfaces on a physical interface which is connected to a trunk port on a layer 2 switch.

Please help.

Thank you
0
Comment
Question by:Savvis
  • 5
  • 2
8 Comments
 
LVL 4

Accepted Solution

by:
pschakravarthi earned 1500 total points
ID: 29259917
There is no other way than to use VLANs.
The PIX interface will be configured as trunk, while for each VLAN you will configure subinterfaces. Assign one VLAN ID per interface

Ex:

interface GigabitEthernet0/1

description "Trunk Connectivity with SW"

speed 100

duplex full

no nameif

no security-level

no ip address




interface GigabitEthernet0/1.100

vlan 100

nameif VLAN100

security-level 80

ip address xxxxxxx


 
0
 

Author Comment

by:Savvis
ID: 29263098
Hi pschakravarthi,
I tried this:
LABFW(config)# int e1
LABFW(config)#nameif
LABFW(config)#no ip address

LABFW(config)# int e1.2
LABFW(config)#nameif ethernet1.2 vlan2 security90
LABFW(config)#ip address vlan2 192.168.2.1 255.255.255.0

LABFW(config)# int e1.3
LABFW(config)#nameif ethernet1.3 vlan3 security80
LABFW(config)#ip address vlan3 192.168.3.1 255.255.255.0

But it idn't work.
Please what else should to do.

Thanks


0
 
LVL 3

Expert Comment

by:zwart072
ID: 29266929
did you configure you're uplink port also as trunk?
0
Evaluating UTMs? Here's what you need to know!

Evaluating a UTM appliance and vendor can prove to be an overwhelming exercise.  How can you make sure that you're getting the security that your organization needs without breaking the bank? Check out our UTM Buyer's Guide for more information on what you should be looking for!

 

Author Comment

by:Savvis
ID: 29269113
Hi zwart072,

What do you mean by "uplink port" ?
My layer switch with 2 vlans works OK when connected to simple trunk link to a router.
But I failed to use it on the PIX:
A pc on vlan2 with this ip: 192.168.2.4/24, gateway 192.168.2.1 (E1.2 of the PIX) cannot ping
the gateway.  I don't know why?
Thanks
0
 
LVL 3

Expert Comment

by:zwart072
ID: 29362332
the port where you are connecting your pix on the switch must be configured as trunk (encapsulation dot1q) port.
0
 

Author Comment

by:Savvis
ID: 29462990
Hi All,

The issue is version

I upgraded the PIX from 6.3(4) to 7.2(2).  

Everything works OK now.

Thanks
0
 

Author Comment

by:Savvis
ID: 29463122
Thks
0
 

Author Closing Comment

by:Savvis
ID: 31709635
Thanks
0

Featured Post

Become an IT Security Management Expert

In today’s fast-paced, digitally transformed world of business, the need to protect network data and ensure cloud privacy has never been greater. With a B.S. in Network Operations and Security, you can get the credentials it takes to become an IT security management expert.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Arrow Electronics was searching for a KVM  (Keyboard/Video/Mouse) switch that could display on one single monitor the current status of all units being tested on the rack.
There’s a movement in Information Technology (IT), and while it’s hard to define, it is gaining momentum. Some call it “stream-lined IT;” others call it “thin-model IT.”
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
When cloud platforms entered the scene, users and companies jumped on board to take advantage of the many benefits, like the ability to work and connect with company information from various locations. What many didn't foresee was the increased risk…

589 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question