PIX 5.6 (no E) VLANs?

Currently my PIX 506 is at 6.3(3). I know I need to upgrade it to 6.3(5). The manuals have said that even with an upgrade though VLANs are supported I am not able to create any virtual interfaces. I want to separate my network into multiple security zones. Currently the network is all lumped together. I see the largest zone of maybe 30 IPs, the next zone of maybe 15 IPs, then a few zones of one or two IPs that could be lumped into the first, larger zone if there is no other place to stick them.

Can the 506 do some sort of VLAN tagging (802.1q?), send the packets to a small router, the router sends the packets to a simple, possibly unmanaged switch, then the switch sends the packets to the actual machines?

For the zones where I have more than 24 IPs, more IPs than I have in a 24 port switch, can I jump/patch one switch to the next? Maybe then I have a primary switch (a small one just greater than the number of security zones?) that is jumpered/patched to other switches that are the actual zones?

There's got to be a better way to do this.

Mike

Reply to
Mike
Loading thread data ...

The PIX 506 and 506E support creating a total of 2 virtual interfaces as of 6.3(3). One of the documents indicates 0 allowed, but that document is incorrect.

Yes!

Yes, that would work.

As long as the next switch along supports VLAN trunking of at least 2 VLANs. Then if you need to, set some ports on that switched to be untagged member of one of the VLANs and set other ports to be untagged members of the second VLAN, and chain together switches as needed. The official limit is 7 switches chained together, but it is almost certain that in your situation you would be able to do more than that if you really needed to.

Reply to
Walter Roberson

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.