Look for advices with Cisco Router and PIX Firewall

Feb 03, 2005 4 Replies

I need some advices from you with getting a PIX Firewall for our network.



We have a Cisco 2621 Router, and want to increase our security level by putting a PIX (501 or 515) Firewall behind it. Some people said PIX is able to act as Router, and it makes things complicate and unnecessary by routing twice with both Router 2621 and PIX 515. Hopefully you would give me an overall answer as experts.



Another question is: What do you think is the best way to the PIX installation in our network?



Our Cisco 2621 has 2 fastEthernet interfaces, so I am using it for 2 subnets. One is 66.XXX.XXX.XXX with global IP, while another is



192.168.XXX.XXX with local IP. I feel it may not be possible to give both subnets a better security with only one PIX Firewall, so I may only be able to product the 66.XXX.XXX.XXX subnet, which is more important for us.

Following is my network layout with the new PIX. Please give me some advices.



Internet | | Router 2621 / \\ / \\ PIX 515 192.168.XXX.XXX / / 66.XXX.XXX.XXX (Global IP)



Your help will be very appreciated. Thanks in advance.



Joe


I agree with what "SysAdm" wrote. Are you a networking guy or a server guy? If you are not a networking/security guy get one. What you are doing needs careful planning and implementation.

I have noticed in my years that people that drop a firewall in and think they are secure, just be casue they have a firewall, are worse off than those without one. A false sense of security can be very, very costly.

Right tool for the right job. Get a networking/security guy in there and get it done right. Remember also, that firewalls require maintenance. You need to monitor for patches/IOS upgrades, monitor the logs and adjust rules when something arises.

Michael

Yes, there IDS was not very good. Supposedly they are working on it. In either case they are a very good Firewall, Router, Switch, VPN and VoIP company...And gaining ground quickly in SONET and DWDM.

I still will check out Cisco before anyone else....

Michael

to be honest you would be better off getting a consultant in for a couple of weeks. its really not just as straightforward as plonking a firewall into your network and carrying on.

SysAdm

And, as an additional layer, do not think Cisco Systems has the answer for everything. Really, really... as an example, they sucks at IDS. This is not their core business, flooding the world with their 42xx but they have the channel to sell those, they have ;-)

RC

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required