506E and multiple web servers

A couple questions about the 506E that even a rep from Cisco didnt give me clear answers on...

  1. I have (2) seperate web servers with Internal IPs of

192.168.1.10

192.168.1.11

that I would like to answer on port 80 and 443 only via (2) Public IPs on the same subnet/gateway

aaa.bbb.ccc.ddd aaa.bbb.ccc.eee

So

aaa.bbb.ccc.ddd (port: 80/443) -> 192.168.1.10:80 (port 80/443) aaa.bbb.ccc.eee (port: 80/443) -> 192.168.1.11:80 (port 80/443)

Can the following be done with a PIX 506E?

  1. Is there a limit to how many distinct publicly accessible web servers I can sit behind the 506E?

  1. The user session and bandwidth limits on the 506E seem good enough for my needs. Is there a better CISCO PIX or security solution for protecting a few web servers?

Reply to
stevem123
Loading thread data ...

The above is not a proble mat all.

When you run out of memory for the translations. Somewhere over

30,000.

There are no bandwidth limits possible on the PIX 506E. To get bandwidth limits, you need PIX 7.x software, which requires a PIX 515, 515E, 525, or 535. There is also the Cisco ASA 5500 series which has the same base software but includes additional inspections (e.g., anti-virus).

Other than that... it depends on your bandwidth needs, interface needs, and the other features you need. For example, a Cisco 871 can do quite a lot (including traffic shaping), and is fast enough for typical commercial connections, but if you happen to be running your web servers on gigabit pipes you need a PIX 515E or higher PIX.

Reply to
Walter Roberson

Thanks for the quick reply Walter.

Ordering a 506E now...

Reply to
stevem123

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.