PIX Firewall with Screening IOS Router
In this scenario, the Cisco IOS router is used as the screening router to provide basic filtering of traffic coming from the Internet. The PIX firewall provides the more robust firewall features (see Figure 9-10).
|
Figure 9-10: Sample Cisco PIX Firewall with Cisco IOS Screening Router |
||
The sample configurations in Listings 9-2 and 9-3 depict the implementation of the following Internet access security policy:
• Device (screening router and firewall) access is through TACACS+ authentication and authorization
• The screening router has simple anti-spoofing filters
• Two illegal networks (192.168.0.0 and 10.0.0.0) must make use of NAT to convert to the legal address given by the ISP of 192.150.50.0
• Hosts on the 10.0.0.0 network can access everything
• Hosts on the 192.168.0.0 network can access the Internet but cannot access hosts on the 10.0.0.0 network
• Only Internet traffic from 144.254.0.0 can access the FTP server whose illegal 192.168.0.6 address must be assigned the legal address 192.150.50.6
• The FTP traffic must be authenticated using TACACS+
• All Internet Web (HTTP) traffic is directed to host 192.168.0.2 (it must be assigned the legal address of 192.150.50.9)
• All outbound Web traffic is sent to do a URL check by way of the WebSense server
• All Internet mail (SMTP) traffic is directed to host 10.0.1.99 (it must be assigned the legal address of 192.150.50.7)
Continue reading here: Disables access to minor TCP services such as echo
Was this article helpful?