PIX firewalling web servers

PIX firewalling web servers

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
PIX firewalling web servers Daniel Foster 07-23-2004
Posted by Daniel Foster on July 23, 2004, 4:06 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi,

We need to run a firewall in front of our web servers. They are on
multiple subnets, so the solution would seem to be to have the internet
connection coming into a perimeter router, then to the firewall, then to
an internal router and out to the servers. I'm having a bit of
difficulty finding any examples of this configuration, although it must
be in use a lot. Could anyone run through the specifics or provide an
example configuration? If possible I'd like to avoid running NAT and PAT.

--
Daniel


Posted by Wolfgang Kueter on July 23, 2004, 6:41 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Daniel Foster wrote:

> Hi,
>
> We need to run a firewall in front of our web servers.

- Why?
- What kind of 'firewall'? Packet filter or proxy?

> They are on
> multiple subnets, so the solution would seem to be to have the internet
> connection coming into a perimeter router, then to the firewall, then to
> an internal router and out to the servers.

Ever thought of using VLAN's?

> I'm having a bit of
> difficulty finding any examples of this configuration, although it must
> be in use a lot. Could anyone run through the specifics or provide an
> example configuration? If possible I'd like to avoid running NAT and PAT.

The PIX is not a router.

Wolfgang
--
A foreign body and a foreign mind
never welcome in the land of the blind
Peter Gabriel, Not one of us, 1980


Similar ThreadsPosted
Re: PIX firewalling web servers July 26, 2004, 10:35 am
Firewalling IP Multicast August 8, 2005, 7:30 pm
Firewalling Features on Ethernet Switches June 23, 2005, 10:35 am
contacts and experience about linux firewalling - ipcop March 11, 2005, 12:16 pm
Firewalling at the domain users level instead of network level July 18, 2004, 7:52 am
5XP Virtual Servers AND SSH August 3, 2005, 6:29 pm
netcreen 25 dmz web servers October 30, 2005, 10:50 am
Multiple TCP/HTTP servers with only one IP : how to ? April 23, 2005, 4:40 am
106023: Deny tcp src outside from WWW Servers September 7, 2005, 5:04 am
pix and multiple syslog-ng servers October 25, 2006, 2:09 pm

The site map in XML format XML site map

Contact Us | Privacy Policy