Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: PIX question? |
|---|---|
| Date: | Mon, 24 Jan 2005 13:24:09 -0700 |
since each vlan on the pix is setup as a logical interface, the firewall treats it as if it were routing traffic from one interface to another even though they are all connected to the same physical port. So providing your core switch can handle the vlans and can route the traffic destined from one vlan to the other to the pix, the pix should be able to handle this. Thanks, Alex O. Ostberg Network Security Specialist - State of Montana Office: 406.444.4557 Fax: 406.444.2701 Email: aostberg@mt.gov -----Original Message----- From: Pablo Hauser [mailto:pablohauser@yahoo.com.ar] Sent: Friday, January 21, 2005 12:17 PM To: 'Dimitri'; firewalls@securityfocus.com Subject: RE: PIX question? Dimitri, PIX firewall doesn't route traffic between interfaces as Checkpoint-Nokia does, just NAT it. Not even think about routing in the same interface... Taking this speech as the bible of PIX troubles, I really don't think that could work... But if it does, tell as how!! :) __________________________________________________ Pablo D. Hauser Security Operations Center IMPSAT -----Mensaje original----- De: Dimitri [mailto:spy4kr@yahoo.co.kr] Enviado el: Miércoles, 19 de Enero de 2005 13:47 Para: firewalls@securityfocus.com Asunto: PIX question? Hi all, I'm auditing a PIX config for version 6.3(4). It has an inside and outside interface only. The inside interface is defined with 1 physical and 2 logical vlans. These are nat'd to the outside. We have a series of static routes binding the same ip on each of the vlans (e.g "static (inside,vlan1) ip1 ip1 netmask ...."). This part I don't understand very well. We've defined rules that explicitly permit access to services (eg. SMTP) from one vlan to another on the same interface. We have a catalyst switch, if (really big IF) this can force the vlans to route traffic to the firewall this might actually work. However, I am very sceptical that this will work and the firewall can actually police traffic between the vlans. Even if it does it seems unnecessarily complex and subject to error. I'd like your opinion on this configuration. Thanks in advanced.
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: PIX question?, Chris Buechler |
|---|---|
| Next by Date: | Re: pix log analyser ?, Chris Buechler |
| Previous by Thread: | Re: PIX question?, Chris Buechler |
| Next by Thread: | Pix performance, Norwich University - Information Security |
| Indexes: | [Date] [Thread] [Top] [All Lists] |