Need help settling this bet: Third Interface on a 506e????

i have a bet to settle with a co-worker.

i thought for sure i read that the 506e with 6.3.4 now supports a DMZ interface but my old-school co-worker keeps pointing me to this page:

formatting link
by looking at table 6-2, it states that Table 6-2 Maximum Number of Interfaces Supported on PIX Firewall Models

Model Restricted License1 Unrestricted License Total Interfaces Physical Interfaces Logical Interfaces Total Interfaces Physical Interfaces Logical Interfaces

PIX 506/506E NA NA NA 2 2 Not supported

The "Not supported" part was the number of logical interfaces.

Hence, he WAS correct.

However, before i pull the rug from him, i looked up that the recent release 6.3.4:

formatting link

VLAN Support Added to the PIX 506/506E This release introduces VLAN support for PIX 506/506E, enabling these platforms to be a low-cost DMZ enabled solution. With this new PIX support, users may implement additional logical interfaces, allowing them to securely host an external Web site, a secure email server, or even an extranet.

By adding support for the IEEE 802.1q VLAN tags, 506/506E Firewalls now feature added flexibility in managing and provisioning the firewall. This feature enables the decoupling of IP interfaces from physical interfaces, making it possible to configure logical IP interfaces independently.

VLAN feature support is added to the interface command.

=B7A maximum of two logical interfaces may be configured on the

506/506E, thus providing a maximum of four interfaces (2 physical and 2 logical) on these platforms.

=B7When 506 and 506E are used as VPN hardware clients, logical interfaces on the 506/506E cannot be used to initiate a VPN tunnel.

=B7If the VLAN ID is set to 4095, the interface name cannot be modified with the nameif command. It may not be appropriate to use VLAN ID 4095 because of this issue.

For configuration information, refer to "Configuring PIX Firewall with VLANs" in the Cisco PIX Firewall and VPN Configuration Guide. For a complete description of the command syntax for these new commands, refer to the Cisco PIX Firewall Command Reference.

From the above statement, 506e now officially support DMZ through vlans right?

I need an unequivocal answer so i can win my bet! lolz!

~Misty.

Reply to
Misty Chen
Loading thread data ...

:i have a bet to settle with a co-worker.

:i thought for sure i read that the 506e with 6.3.4 now supports a DMZ :interface

It does.

:However, before i pull the rug from him, i looked up that the recent :release 6.3.4:

:VLAN Support Added to the PIX 506/506E

Right.

:>From the above statement, 506e now officially support DMZ through vlans :right? :I need an unequivocal answer so i can win my bet! lolz!

The main PIX documentation often takes time to catch up. It is not unknown for it to be wrong through an entire release generation until someone points out the problem and they fix it.

With respect to number of interfaces supported, the Configuration Guide has historically been more accurate.

formatting link
But to settle the question definitively:

slayer(config)# show ver

Cisco PIX Firewall Version 6.3(4)

Hardware: PIX-506E, 32 MB RAM, CPU Pentium II 300 MHz

slayer(config)# interface ethernet0 vlan999 logical slayer(config)# show int interface ethernet0 "outside" is up, line protocol is up Hardware is i82559 ethernet, address is 000e.d7a2.da20 [...] interface vlan999 "intf2" is up, line protocol is up Hardware is i82559 ethernet, address is 000e.d7a2.da20 MTU 1500 bytes, BW 100000 Kbit full duplex 0 packets input, 0 bytes 0 packets output, 0 bytes interface ethernet1 "inside" is up, line protocol is up Hardware is i82559 ethernet, address is 000e.d7a2.da21 [...]

Reply to
Walter Roberson

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.