Network Setup Help!!!

Network Setup Help!!!

Secure Home | Search | About
 General Computer Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Network Setup Help!!! tractng 09-03-2005
Posted by on September 3, 2005, 9:50 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Guys,

Currently my network sits behind the pix 501. I have very important
personal data (financial statements, etc). Only port open is 25 at the
File Server.


dsl router ->switch-> pix(66.151.99.1 outside)-->File Server
(192.149.115.2 inside) |
|
|
|
---> Outside PC (outside the lan)
(66.159.99.2 outside NIC1)
(inside IP address NIC2??)

The purpose of the 'Outside PC' sitting out of my network is for
testing, ftp, etc. But I like to be able to access from the inside pc
(File Server) to the Outside PC vice versa.

How should I configure so I have the tightest security? VPN, windows
routing, etc?

Btw, all these IPs are just made up.


TIA
Tony



Posted by on September 3, 2005, 9:54 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

Guys,

The 'Outside PC' connects to the switch. The drawing was misaligned.

Tony



Posted by Leythos on September 4, 2005, 5:05 am
If you were  Registered and logged in, you could reply and use other advanced thread options
tractng@gmail.com says...
> Guys,
>
> Currently my network sits behind the pix 501. I have very important
> personal data (financial statements, etc). Only port open is 25 at the
> File Server.
>
>
> dsl router ->switch-> pix(66.151.99.1 outside)-->File Server
> (192.149.115.2 inside) |
> |
> |
> |
> ---> Outside PC (outside the lan)
> (66.159.99.2 outside NIC1)
> (inside IP address NIC2??)
>
> The purpose of the 'Outside PC' sitting out of my network is for
> testing, ftp, etc. But I like to be able to access from the inside pc
> (File Server) to the Outside PC vice versa.
>
> How should I configure so I have the tightest security? VPN, windows
> routing, etc?
>
> Btw, all these IPs are just made up.

If you connect the PC so that it bridges both networks you don't need a
firewall, as you won't have any real protection for the LAN.

If you have more than one Public IP, put your trusted computers on the
PIX and IP1, then setup a cheap Linksys router on Public IP2 and put the
test computer on that device - do not connect it to the LAN of the PIX.

--

spam999free@rrohio.com
remove 999 in order to email me


Posted by Volker Birk on September 4, 2005, 9:35 am
If you were  Registered and logged in, you could reply and use other advanced thread options
tractng@gmail.com wrote:
> dsl router ->switch-> pix(66.151.99.1 outside)-->File Server
> (192.149.115.2 inside) |
> |
> |
> |
> ---> Outside PC (outside the lan)
> (66.159.99.2 outside NIC1)
> (inside IP address NIC2??)
> The purpose of the 'Outside PC' sitting out of my network is for
> testing, ftp, etc. But I like to be able to access from the inside pc
> (File Server) to the Outside PC vice versa.
> How should I configure so I have the tightest security? VPN, windows
> routing, etc?

If I interpret right, the "Outside PC" has one interface into
the internal Zone, and one into the outside zone. This is a design
flaw with your zone concept. No simple host should be in more than one
zone at a time.

Yours,
VB.
--
"Es kann nicht sein, dass die Frustrierten in Rom bestimmen, was in
deutschen Schlafzimmern passiert".
Harald Schmidt zum "Weltjugendtag"


Similar ThreadsPosted
Using Netbui on a w2k setup June 26, 2004, 10:04 am
RBAC setup December 1, 2005, 8:44 pm
Changes in setup/configuration for VPN and IPSec?? April 26, 2007, 4:58 am
How to setup a ssh tunnel for telnet with openssh? July 6, 2005, 5:04 pm
Network Restructuring (Network Design and Equipment) May 16, 2006, 9:38 am
Howto setup a certificate authority and create a signed certificate using openssl on Debian sarge March 16, 2005, 10:39 am
network storage December 17, 2005, 6:56 am
Copy HDD Across Network October 3, 2007, 9:50 am
Looking for a new Network Security Solution April 6, 2004, 5:46 am
XP shows only 8 characters of (WEP) Network key. April 6, 2005, 2:19 pm

The site map in XML format XML site map

Contact Us | Privacy Policy