Go Back   Velocity Reviews > Newsgroups > Cisco
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply

Cisco - newbe question on configuration

 
Thread Tools Search this Thread
Old 06-23-2004, 07:24 PM   #1
Default newbe question on configuration


I am trying to help out a friend. They have a 2611 with the IOS Firewall
license but the firewall is not configured. It has two ethernet interfaces,
only one is currently in use. They want to activate the IOS firewall
feature set. They have a Web server that is on thier 192.168.0.0 network
that they want to make accessible. They do not want a DMZ since they use
the server for other applications (tiny company) and it connects to a
database somewhere on the private network and the person there who set up
the web server does not want to have the web server and the database on
different networks. The WAN interface is part of a /30 network (fake i.e.
1.1.1.3/30). I have been told that they have another discontiguous address
block (fake i.e. 2.2.2.10/2 that is not in use. My input was to purchase
a standalone server and put it on the DMZ but they dont want to do that. So
I think these are the options
1. Dual home the webserver so it sits on both networks and assign the two
ethernet ports to the different networks one on 192.168.0.0 and the other on
2.2.2.10/28. The 2.2.2.10 with only http, https and ftp. This concerns me
from a security standpoint.
2. Use only a single router ethernet interface 0/0 and bind it with two
addresses 192.168.0.1 primary and 2.2.2.10 secondary and to NAT a 2.2.2.x
address to a 192.168.0.x address. I believe I may need to kill the split
horizon to make that work.

Are there other better options? Any suggestions?




Michael Huffaker
  Reply With Quote
Old 07-16-2004, 11:24 PM   #2
Kevin Widner
 
Posts: n/a
Default Re: newbe question on configuration
"Michael Huffaker" <> wrote in message news:<lVjCc.843$Y_5.514@fed1read02>...
> I am trying to help out a friend. They have a 2611 with the IOS Firewall
> license but the firewall is not configured. It has two ethernet interfaces,
> only one is currently in use. They want to activate the IOS firewall
> feature set. They have a Web server that is on thier 192.168.0.0 network
> that they want to make accessible. They do not want a DMZ since they use
> the server for other applications (tiny company) and it connects to a
> database somewhere on the private network and the person there who set up
> the web server does not want to have the web server and the database on
> different networks. The WAN interface is part of a /30 network (fake i.e.
> 1.1.1.3/30). I have been told that they have another discontiguous address
> block (fake i.e. 2.2.2.10/2 that is not in use. My input was to purchase
> a standalone server and put it on the DMZ but they dont want to do that. So
> I think these are the options
> 1. Dual home the webserver so it sits on both networks and assign the two
> ethernet ports to the different networks one on 192.168.0.0 and the other on
> 2.2.2.10/28. The 2.2.2.10 with only http, https and ftp. This concerns me
> from a security standpoint.
> 2. Use only a single router ethernet interface 0/0 and bind it with two
> addresses 192.168.0.1 primary and 2.2.2.10 secondary and to NAT a 2.2.2.x
> address to a 192.168.0.x address. I believe I may need to kill the split
> horizon to make that work.
>
> Are there other better options? Any suggestions?



Use option 3, change WAN interface to use the other public range, the
/28. This gives you a few more IP's to work with. NAT the server out
to an IP address of its own on the WAN, PAT everything else. Turn on
firewall feature set. Done. Way more simple.


Kevin Widner
  Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
DVD shrink newbe question. Can it change video standards? Mike DVD Video 1 08-28-2007 01:43 AM
"Installing two drives" question - what next? Jim A+ Certification 12 08-07-2005 01:19 PM
Re: Good morning or good evening depending upon your location. I want to ask you the most important question of your life. Your joy or sorrow for all eternity depends upon your answer. The question is: Are you saved? It is not a question of how good God DVD Video 3 04-25-2005 04:19 PM
Re: Good morning or good evening depending upon your location. I want to ask you the most important question of your life. Your joy or sorrow for all eternity depends upon your answer. The question is: Are you saved? It is not a question of how good Filthy Mcnasty DVD Video 0 04-25-2005 04:29 AM
Re: Safe Mode Question (A+ question) Gordon Findlay A+ Certification 0 06-16-2004 10:48 AM




SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46