Firewall Wizards mailing list archives

PIX v7: routing without NAT


From: Vahid Pazirandeh <vpaziran () yahoo com>
Date: Wed, 11 Jan 2006 09:42:35 -0800 (PST)

I have public IP addresses 1.1.1.65 to 1.1.1.96 available.  I'd like the
servers behind my PIX 515E (Restricted License) to use the public IP addresses.
 One hop away is my ISPs router sitting at 1.1.1.1.  So the network looks like
this:

ISP router: 1.1.1.1

[ISP router]------[PIX]------[switch]---[my servers]

I'm having difficulty configuring the PIX outside/inside interface in order to
allow the servers to communicate with the internet.

If I make the inside interface 1.1.1.65/255.255.255.224, then what do I make
the outside interface?  Since two interfaces cannot overlap on the same subnet.

I've tried playing around with the netmask and, at times, I'm able to ping
1.1.1.1, however I cannot ping the internet (ISP router doesn't seem to be
routing me out?).

I have heard of PIX having "Transparent Mode" but I'm not too clear on how that
is configured.  Do I need an Unrestricted License for that?  Is it necessary?

The _end goal_ is to have my servers sitting on different VLANs and the PIX
will act as the 802.1q trunk.  This way I can filter traffic between VLANs
(which is my intention), and filter traffic with the internet.

As I am a novice, any helpful critcism is welcome.

Thanks!

-Vahid

=============================================
 "Make it better before you make it faster."
=============================================

__________________________________________________
Do You Yahoo!?
Tired of spam?  Yahoo! Mail has the best spam protection around 
http://mail.yahoo.com 
_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: