Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Firewalls
[Top] [All Lists]

PIX question?

Subject: PIX question?
Date: 19 Jan 2005 16:47:03 -0000


Hi all,

I'm auditing a PIX config for version 6.3(4).  It has an inside and outside 
interface only.  The inside interface is defined with 1 physical and 2 logical 
vlans.  These are nat'd to the outside.   

We have a series of static routes binding the same ip on each of the vlans (e.g 
"static (inside,vlan1) ip1 ip1 netmask ....").  This part I don't understand 
very well. 

We've defined rules that explicitly permit access to services (eg. SMTP) from 
one vlan to another on the same interface. We have a catalyst switch, if 
(really big IF) this can force the vlans to route traffic to the firewall this 
might actually work.  However, I am very sceptical that this will work and the 
firewall can actually police traffic between the vlans.   Even if it does it 
seems unnecessarily complex and subject to error.   

I'd like your opinion on this configuration.

Thanks in advanced.

<Prev in Thread] Current Thread [Next in Thread>