Vlan and PIX question

Vlan and PIX question

NewsGroups | Search | Tools
 comp.dcom.sys.cisco  Post an article  get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content  add this group's latest topics to your Google content  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Vlan and PIX question Rob 03-28-2006
Posted by Rob on March 28, 2006, 11:16 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi,
We are going to share our Internet connection feed with a WAN connection.
The ISP will do it using VLAN. My plan is to bring the feed to a swtich
which supports VLAN and then split it to ports with different VLN ID, and
take the Internet to the outside PIX (515, 6.3). My question.... Is that
doable? Do I need to change anything on PIX? Do you see any issue with
VLANing and PIX as long as I use a swith to split VLANs.
Thanks in advance for any help. Rob



Spring Sale Save 20% Banner - Sale Ended 5/3/07 So Updated to NonPromo Ad
Posted by Merv on March 28, 2006, 1:50 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
You should give consideration to encrypting the WAN traffic using IPSEC.


Posted by Lutz Donnerhacke on March 28, 2006, 2:02 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
* Rob wrote:
> doable? Do I need to change anything on PIX? Do you see any issue with
> VLANing and PIX as long as I use a swith to split VLANs.

No problems. Have fun.

Posted by Walter Roberson on March 28, 2006, 7:58 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
>We are going to share our Internet connection feed with a WAN connection.
>The ISP will do it using VLAN. My plan is to bring the feed to a swtich
>which supports VLAN and then split it to ports with different VLN ID, and
>take the Internet to the outside PIX (515, 6.3). My question.... Is that
>doable? Do I need to change anything on PIX? Do you see any issue with
>VLANing and PIX as long as I use a swith to split VLANs.

The PIX 515 running 6.3 software can handle several 802.1Q VLANs
directly -- that is, you could trunk several VLANs to the 515
and configure "logical" interfaces and pull the VLANs off as if
they were seperate physical interfaces. Whether you want to do that
or not depends on whether you are providing security for the other VLANs
or if they belong to other organizations.

If you are just using a plain stream out the 515 and the switch
is encapsulating into a VLAN, then you *might* need to reduce
the sysopt mss and/or the MTU by a few bytes, if there is any
equipment in the path that does not know about the extended
frame size that is often allowed for 802.1Q tagged packets.

Similar ThreadsPosted
VLAN question ? August 16, 2004, 7:26 pm
VLAN question - Need help !! November 26, 2004, 1:53 am
Cat OS VLAN question July 7, 2006, 6:32 pm
VLAN Question March 8, 2007, 3:06 pm
VLAN Question July 25, 2007, 12:41 pm
VLAN Question August 22, 2007, 3:01 pm
Basic VLAN question. June 27, 2005, 4:21 pm
Native VLAN question November 22, 2005, 5:58 am
vlan and vpn config question January 12, 2006, 10:04 am
basic vlan pix 6.3 question July 25, 2006, 2:26 am

other useful resources:
The Federal Communications Commission (FCC)
Telecommunications Industry Association
Electronic and Software Security Products and Services
International Telecommunication Union

Custom CGI Perl and PHP programming by 1-Script.com

Contact Us | Privacy Policy
The site map in XML format XML site map