|
Posted by Wolfgang Kueter on April 8, 2007, 8:25 am
If you were Registered and logged in, you could reply and use other advanced thread options
zii kell wrote:
> [...]
> The simple way would be to create a DMZ, but the PIX 501 does not have a
> dedicated interface for this. Only interface0 (outside) and interface1
> (inside). The inside interface is an internal four port switch.
>
> Any clues on how this might work?
Well, if a device does not offer enough physical interfaces normally one
would use VLANs (of course a switch that supports VLANs must be used in
that case). Unfortunately though the Pix from PIXOs version 6.3 upwards
supports VLANs the PIX 501 (which is a classic SOHO model and therefore is
not intended to be used for bigger installations) does not.
http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_configuration_guide_chapter09186a0080172786.html#wp1113411
Solution: Either get a bigger PIX or use something else. Alternatives from
other vendors like Clavister, Fortigate, Netscreen/Juniper etc. do exist.
Wolfgang
|