Firewall Wizards mailing list archives
RE: Disecting the Cisco PIX
From: "Noonan, Wesley" <Wesley_Noonan () bmc com>
Date: Tue, 30 Jul 2002 14:24:52 -0500
inline Wes Noonan, MCSE/CCNA/CCDA/NNCSS Senior QA Rep. BMC Software, Inc. (713) 918-2412 wnoonan () bmc com http://www.bmc.com
-----Original Message----- From: Art Mason [mailto:a.c.mason () sbcglobal net] Sent: Tuesday, July 30, 2002 11:40 To: firewall-wizards () honor icsalabs com Subject: [fw-wiz] Disecting the Cisco PIX Out of curiosity, has anyone here ever cracked open any of the Cisco PIX series firewalls chassis? From what I've gathered by reading up on their product information and by what people have said about them in various mailing lists and newsgroups, they are actually built on an x86 hardware platform w/ a Celeron 300MHz (PIX 506E) to Pentium III 1.0GHz (PIX 535) CPU and anywhere from 32MB to 1GB RAM .
Yeah. Dunno the specs off the top of my head, but they are essentially PCs.
I understand the storage media to be compact flash (4-16MB capacity) and on the low-end models w/ 10Mb throughput, they actually use an ISA NIC in the chassis.
Dunno about the ISA NIC thing, but I know people that have managed to get them to work using a regular old desktop NIC... though it is not supported by Cisco for obvious reasons.
I've also read that the PIX doesn't support local logging (everything needs to be redirected to a syslog server). Can anyone confirm any of this?
Local logging in what capacity? To the file system? No, not realistically. To the console, yeah. To a history buffer, yeah.
If so, why couldn't one just throw OpenBSD onto some flash media, drop a couple of Intel Pro100+ dual-port NICs in a 2U rackmount case, maybe offload some of the VPN stuff onto an ASIC-based encryption acceleration card, and save some big bucks, granted they know how to set up PF from the CLI?
What big bucks? The bucks for the hardware? The bucks for the person who can write the code? The bucks for the person who maintains the code? Not sure I follow. I suppose that small shops all over the place that have specialized Unix expertise actually do this all the time, but it think that it is more a niche scenario than anything else.
This is just something I've been wondering about for a while, and was curious as to what others in the know had to say about it. Thanks in advance.
Interesting idea, in certain circumstances. _______________________________________________ firewall-wizards mailing list firewall-wizards () honor icsalabs com http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
Current thread:
- Disecting the Cisco PIX Art Mason (Jul 30)
- Re: Disecting the Cisco PIX Evan Wagner (Jul 30)
- Re: Disecting the Cisco PIX Michael C. Ibarra (Jul 30)
- Re: Disecting the Cisco PIX Kevin Steves (Jul 30)
- <Possible follow-ups>
- RE: Disecting the Cisco PIX Noonan, Wesley (Jul 30)