Configuring a PIX Firewall
This section takes a look at configuring the PIX Firewall software and the six basic commands used to configure a PIX Firewall.
Figure 6-5 displays a typical DMZ and perimeter network between the inside (protected) and outside (public) networks.
Figure 6-5 Typical PIX Firewall Logical Setup
Figure 6-5 Typical PIX Firewall Logical Setup

- 201.201.201.1 255.255.255.0
PIX Firewall Configuration Task List
The following steps show you how the PIX Firewall software is configured for the scenario in Figure 6-5:
Step 1 Name the inside and outside interfaces and assign the security levels (in global configuration mode):
nameif hardware_id if_name security_level vlan_id
The nameif command lets you assign a name to an interface. You can use this command to assign interface names if you have more than two network interface circuit boards in your PIX Firewall. The first two interfaces have the default names inside and outside. The inside interface has default security level 100, and the outside interface has default security level 0.
Table 6-3 describes the PIX Firewall command nameif as documented on the Cisco Documentation CD-ROM.
|
Syntax |
Description |
|
hardware_id |
The hardware name for the network interface that specifies the interface's slot location on the PIX Firewall motherboard. Interface boards are numbered from the leftmost slot nearest the power supply as slot 0. The internal network interface must be in slot 1. The lowest security_level external interface board is in slot 0, and the next lowest security_level external interface board is in slot 2. |
|
if_name |
A name for the internal or external network interface of up to 48 characters in length. This name can be upper- or lowercase. By default, the PIX Firewall names the inside interface inside, the outside interface outside, and any perimeter interface intfn, where n is 2 through 5. |
|
security_level |
Either 0 for the outside network or 100 for the inside network. Perimeter interfaces can use any number between 1 and 99. By default, the PIX Firewall sets the security level for the inside interface to security100, and the outside interface to security0. The first perimeter interface is initially set to security10, the second to security15, the third to security20, and the fourth to security25. Check the latest Cisco IOS bulletins for the number of hardware interfaces supported per PIX Firewall. |
|
vlan_id |
The VLAN identifier; for example, vlan10, vlan20, etc. The VLAN identifier is configured with the interface command. |
Step 2 Identify the hardware interfaces, speed, and duplex type installed with the following interface command:
interface hardware_id [hardware_speed] [shutdown]
In Figure 6-5, the following commands are configured:
interface ethernet0 10full interface ethernetl 10full
Table 6-4 defines and describes the options for the interface command, as documented on the Cisco Documentation CD-ROM.
|
Option |
Description |
|
hardware_id |
Identifies the network interface type. Possible values are ethernetO, ethernetl to ethernetn, or gb-ethernetn, depending on how many network interfaces are in the PIX Firewall. |
|
hardware_speed |
Network interface speed (optional). |
|
shutdown |
Disables an interface. |
Step 3 Define the inside and outside IP addresses.
The ip address if_name ip_address [netmask] command lets you assign an IP address to each interface.
Use the show ip command to view which addresses are assigned to the network interfaces.
In Figure 6-5, the IP address assignment is defined as follows:
ip address inside 201.201.201.1 255.255.255.0 ip address outside 131.108.1.1 255.255.255.0
|
Option |
Description |
|
if_name |
The internal or external interface name designated by the nameif command |
|
ip_address |
PIX Firewall unit's network interface IP address |
|
netmask |
Network mask of ip_address |
Step 4 Define NAT with the nat command.
The nat command lets you enable or disable address translation for one or more internal addresses. Address translation means that when a host starts an outbound connection, the IP addresses in the internal network are translated into global addresses. NAT lets your network have any RFC 1918 IP addressing scheme, and the firewall protects these addresses from visibility on the external network.
The command syntax is as follows:
nat [(if_name)] nat_id local_ip [netmask [max_conns [em_limit]]] [norandomseq]
In Figure 6-5, the following pool is assigned to the PIX Firewall: nat (inside) 1 0.0.0.0 0.0.0.0
This command enables all inside hosts to access the Internet.
Table 6-6 defines the options of the nat command, as documented on the Cisco Documentation CD-ROM.
|
Option |
Description |
|
if_name |
Any internal network interface name. |
|
nat_id |
An arbitrary positive number between 0 and 2 billion. Specify 0 with IP addresses and netmasks to identify internal networks that desire only outbound identity address translation. Use 0 with the access-list option to specify traffic that should be exempt from NAT. The access list should already be defined, otherwise PIX Firewall gives an error message. |
|
local_ip |
Internal network IP address to be translated. You can use 0.0.0.0 to allow all hosts to start outbound connections. You can abbreviate 0.0.0.0 local_ip as 0. |
|
netmask |
Network mask for local_ip. You can use 0.0.0.0 to allow all outbound connections to translate using IP addresses from the global pool. |
|
max_conns |
The maximum TCP connections permitted from the interface you specify. |
|
em_limit |
The embryonic connection limit. The default is 0, which means unlimited connections. Set it lower for slower systems and higher for faster systems. |
|
norandomseq |
Do not randomize the TCP packet's sequence number. Use this option only if another inline firewall is also randomizing sequence numbers and the result is scrambling the data. Use of this option opens a security hole in the PIX Firewall. |
Step 5 Define the global pool.
The global command defines a pool of global addresses. The global addresses in the pool provide an IP address for each outbound connection, and for those inbound packets resulting from outbound connections.
If the nat command is used, you must also use the global command. Basically, when an outbound IP packet is sent from the inside network, the PIX Firewall extracts the source address and compares that address to the list of current NAT translations. If there is no entry, a new entry is created. If a NAT entry already exists, the packet is forwarded.
The PIX syntax for the global command is defined as follows:
global [(if_name)] nat_id global_ip [-global_ip] [netmask global_mask] [interface]
In Figure 6-5, the pool of addresses is defined as follows:
global (outside) 1 192.192.1.2-192.192.1.30 netmask 255.255.255.224
The pool of addresses is typically assigned to you by the InterNIC or your ISP.
Table 6-7 defines the options of the global command, as documented on the Cisco Documentation CD-ROM.
|
Option |
Description |
|
if_name |
The external network where you use these global addresses. |
|
nat_id |
A positive number shared with the nat command that groups the nat and global command statements together. The valid ID numbers can be any positive number up to 2,147,483,647. |
|
global_ip |
One or more global IP addresses that the PIX Firewall shares among its connections. If the external network is connected to the Internet, each global IP address must be registered with the InterNIC. You can specify a range of IP addresses by separating the addresses with a dash (-). You can create a PAT global command statement by specifying a single IP address. You can have more than one PAT global command statement per interface. A PAT can support up to 64,000 xlate objects. |
|
netmask |
Reserved word that prefaces the network global_mask variable. |
|
global_mask |
The network mask for global_ip. If subnetting is in effect, use the subnet mask; for example, 255.255.255.128. If you specify an address range that overlaps subnets, global will not use the broadcast or network addresses in the pool of global addresses. For example, if you use 255.255.255.224 and an address range of 209.165.201.1 to 209.165.201.30, the 209.165.201.31 broadcast address and the 209.165.201.0 network address will not be included in the pool of global addresses. |
|
interface |
Specifies PAT using the IP address at the interface. |
Step 6 Finally, define how to route IP data with the route command.
Use the route command to enter a default or static route for an interface. The PIX Firewall syntax is as follows:
route if_name ip_address netmask gateway_ip [metric]
Configuring Static Routing on a PIX Firewall
Figure 6-5 defines all routes via the perimeter router as follows:
Table 6-8 defines the options of the route command, as documented on the Cisco Documentation CD-ROM.
|
Option |
Description |
|
if_name |
The internal or external network interface name. |
|
ip_address |
The internal or external network IP address. Use 0.0.0.0 to specify a default route. You can abbreviate the 0.0.0.0 IP address as 0. |
|
netmask |
Specify a network mask to apply to ip_address. Use 0.0.0.0 to specify a default route. The 0.0.0.0 netmask can be abbreviated as 0. |
|
gateway_ip |
Specify the IP address of the gateway (the next-hop address for this route). |
|
metric |
Specify the number of hops to gateway_ip. In Figure 6-5, this is 1. |
Example 6-4 displays the full working configuration of the PIX Firewall shown in Figure 6-5. The shaded portions of this display are configuration commands we have entered, and the nonshaded portions are default configurations. One of the advantages of the PIX Firewall, like the Catalysts Ethernet switch, is that you can view the full working and default configuration, unlike Cisco IOS routers, for which the default configuration is not displayed.
Example 6-4 PIX Firewall Full Working Configuration pix# write terminal nameif ethernet0 outside security0 nameif ethernet1 inside security100 hostname pixfirewall fixup protocol ftp 21 fixup protocol http 80 fixup protocol smtp 25 fixup protocol h323 1720 fixup protocol rsh 514 fixup protocol sqlnet 1521 names name 1.1.1.1 abcd name 1.1.1.2 a123456789 name 1.1.1.3 a123456789123456 pager lines 24 logging timestamp no logging standby logging console debugging no logging monitor logging buffered debugging no logging trap logging facility 20 logging queue 512 interface ethernet0 10full interface ethernet1 10full mtu outside 1500 mtu inside 1500
Example 6-4 PIX Firewall Full Working Configuration (Continued)
ip address inside 201.201.201.1 255.255.255.0 ip address outside 131.108.1.1 255.255.255.0 no failover failover timeout 0:00:00 failover ip address outside 0.0.0.0 failover ip address inside 0.0.0.0 arp timeout 14400
|
global (outside) 1 192.192.1 nat (inside) 1 0.0.0.0 0.0. |
2-192.192.1 S.0 |
30 netmask 255.255.255.224 |
|
no rip outside passive |
||
|
no rip outside default |
||
|
no rip inside passive |
||
|
no rip inside default |
||
|
route outside 0.0.0.0 0.0.0 |
0 131.108.1 |
2 1 |
timeout xlate 3:00:00 conn 1:00:00 half-closed 0:10:00 udp 0:02:00 timeout rpc 0:10:00 h323 0:05:00 timeout uauth 0:00:00 absolute no snmp-server location no snmp-server contact snmp-server community public no snmp-server enable traps telnet timeout 5 terminal width 80 : end timeout xlate 3:00:00 conn 1:00:00 half-closed 0:10:00 udp 0:02:00 timeout rpc 0:10:00 h323 0:05:00 timeout uauth 0:00:00 absolute no snmp-server location no snmp-server contact snmp-server community public no snmp-server enable traps telnet timeout 5 terminal width 80 : end
NOTE Note the order of preference for the PIX Firewall when NAT is enabled:
■ Regular NAT
Miscellaneous PIX Firewall Commands
Three other important commands that are commonly used in PIX Firewall configurations are the static, conduit, and alias commands.
The static command creates a permanent mapping (Cisco documentation names or calls this a translation slot or xlate) between a local IP address and a global IP address. Use the static and conduit commands when you are accessing an interface of a higher security level from an interface of a lower security level; for example, when accessing the inside interface from the outside interface.
The command syntax is as follows:
static [(internal_if_name, external_if_name)] global_ip local_ip [netmask network_mask] [max_conns [em_limit]] [norandomseq]
Table 6-9 defines the options of the static command, as documented on the Cisco Documentation CD-ROM.
|
Option |
Description |
|
internal_if_name |
The internal network interface name. The higher-security-level interface you are accessing. |
|
external_if_name |
The external network interface name. The lower-security-level interface you are accessing. |
|
global_ip |
A global IP address. This address cannot be a PAT IP address. The IP address on the lower-security-level interface you are accessing. |
|
local_ip |
The local IP address from the inside network. The IP address on the higher-security-level interface you are accessing. |
|
netmask |
Reserved word required before specifying the network mask. |
|
network_mask |
Pertains to both global_ip and local_ip. For host addresses, always use 255.255.255.255. For network addresses, use the appropriate class mask or subnet mask; for example, for Class A networks, use 255.0.0.0. An example subnet mask is 255.255.255.224. |
|
max_conns |
The maximum number of connections permitted through the static connection at the same time. |
|
em_limit |
The embryonic connection limit. An embryonic connection is one that has started but not yet completed. Set this limit to prevent attack by a flood of embryonic connections. The default is 0, which means unlimited connections. |
|
norandomseq |
Do not randomize the TCP/IP packet's sequence number. Use this option only if another inline firewall is also randomizing sequence numbers and the result is scrambling the data. Use of this option opens a security hole in the PIX Firewall. |
An example of the command is as follows:
static (inside,outside) 192.192.1.33 201.201.201.10 The static command should be used in conjunction with either conduit or access-list. A conduit command statement creates an exception to the PIX Firewall ASA mechanism by permitting connections from one firewall network interface to access hosts on another.
NOTE If a conduit or access list is not configured on the PIX Firewall, then by default all traffic will be dropped, resulting in the PIX Firewall acting like a black hole or bit bucket router. By default, the PIX Firewall will drop all traffic unless configured otherwise.
The clear conduit command removes all conduit command statements from your configuration. The conduit command syntax is defined as follows:
conduit {permit | deny} protocol global_ip global_mask [operator port [port]] foreign_ip foreign_mask [operator port [port]]
Table 6-10 displays the options and command syntax for the conduit command, as documented on the Cisco Documentation CD-ROM.
|
Option |
Description |
|
permit |
Permits access if the conditions are matched. |
|
deny |
Denies access if the conditions are matched. |
|
protocol |
Specifies the transport protocol for the connection. Possible literal values are icmp, tcp, udp, or an integer in the range 0 through 255, representing an IP protocol number. Use ip to specify all transport protocols. |
|
global_ip |
A global IP address previously defined by a global or static command. You can use any if the global_ip and global_mask are 0.0.0.0 0.0.0.0. The any option applies the permit or deny parameters to the global addresses. |
|
global_mask |
Network mask of global_ip. The global_mask is a 32-bit, four-part dotted-decimal address, such as 255.255.255.255. Use 0s in a part to indicate bit positions to be ignored. Use subnetting, if required. If you use 0 for global_ip, use 0 for global_mask; otherwise, enter the global_mask appropriate to global_ip. |
|
foreign_ip |
An external IP address (host or network) that can access the global_ip. You can specify 0.0.0.0 or 0 for any host. If both the foreign_ip and foreign_mask are 0.0.0.0 0.0.0.0, you can use the shorthand any option. |
|
foreign_mask |
Network mask of foreign_ip. The foreign_mask is a 32-bit, four-part dotted-decimal address, such as 255.255.255.255. Use 0s in a part to indicate bit positions to be ignored. Use subnetting, if required. |
|
operator |
A comparison operand that lets you specify a port or a port range. Use without an operator and port to indicate all ports. For example, conduit permit tcp any any. By default, all ports are denied until explicitly permitted. |
|
port |
Service(s) you permit to be used while accessing global_ip or foreign_ip. Specify services by the port that handles them, such as smtp for port 25, www for port 80, and so on. You can specify ports by either a literal name or a number in the range of 0 to 65,535. You can specify all ports by not specifying a port value (for example: conduit deny tcp any any). |
PIX Firewall software version 6.2 allows NAT of external source IP addresses for packets traveling from the outside interface to the inside interface. All functionality available with traditional NAT, such as fixups, stateful failover, dynamic NAT, static NAT, and PAT, are available bidirectionally in this release.
The alias command translates one address into another. The alias command is used when registered addresses have been used in a private network and access is required to the registered address space on the Internet. Consider the following example: the inside network contains the IP subnet address 64.236.16.0/24. Assume this belongs to the website at www.cnn.com.
When inside clients try to access www.cnn.com, the packets do not go to the firewall because the client thinks 64.236.16.0/24 is on the local inside network. To correct this, a net alias is created as follows with the alias command:
alias (inside) 64.236.16.0 131.108.2.0 255.255.255.0
When the inside network client 64.236.16.0 connects to www.cnn.com, the DNS response from an external DNS server to the internal client's query would be altered by the PIX Firewall to be 131.108.2.1-254/24.
NOTE The alias command is replaced in newer versions with a dns keyword in static and nat commands.
Advanced Cisco PIX Commands
Table 6-11 summarizes some of the other useful features on a Cisco PIX Firewall, as documented on the Cisco Documentation CD-ROM.
|
Command |
Use |
|
ca |
Configure the PIX Firewall to interoperate with a Certificate Authority (CA). |
|
Clear the contents of the translation slots. |
|
|
Display NAT translations. The show xlate command displays the contents of only the translation slots. |
|
|
Create, view, or delete a dynamic crypto map entry. |
|
|
failover [active] |
Use the failover command without an argument after you connect the optional failover cable between your primary firewall and a secondary firewall. |
|
fixup protocol |
The fixup protocol commands let you view, change, enable, or disable the use of a service or protocol through the PIX Firewall. |
|
Command |
Use |
|
kill |
Terminate a Telnet session. Telnet sessions to the PIX Firewall must be enabled. |
|
telnet ip_address [netmask] [if_name] |
Specify the permitted host devices for PIX Firewall console access via Telnet. |
Continue reading here: CBAC Configuration Task List
Was this article helpful?