• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

network noob needs help with cisco

geist

n00b
Joined
Jan 1, 2006
Messages
28
ok at my company we have a cisco 3550 powered switch, our internet connection is a fiberooptic but the box that the fiber plugs into outputs a rj45 cable which then plugs into the 3550. 4 of the ports on the 3550 are our static ips, and most of the others are our voip phones, and computers. we have a crappy little netgear that acts as the firewall.

now what id like to know is in a sane company what would be the correct way to set this thing up, not using the piece of crap netgear 4 port/wireless/firewall.
 
How many servers & workstations?

Are you hosting your own e-mail or any web sites?
 
The PIX is a great box, but maybe more than what he needs. It's certainly not "easy" for an admitted network noob to configure properly either.

To the OP, the little Netgear box may not be as bad as it seems.

It really depends on your needs.
 
A pix with 7.0 is easy to setup because of the GUI. If he is not familar witht he CLI he has the pretty GUI to use. I also recommend a pix. I use a ASA now but that is the same thing as a pix, just with more things added in.
 
GTA GB-2000 for the firewall, web-based GUI config , great feature set, great reporting capabilities and overall just excellent enterprise class firewall

I still go by the rule that having a firewall that's not mainstream (PIX) is you best line of defense.

www.gta.com
 
so the pix is just a firewall? its not a router too? do i need a router? the way things are setup right now are really screwed up, our wan comes in and plugs into the 3550 then gets plugged into the netgear which is plugged back into the 3550 and then all of our workstations are plugged intot he 3550 which get dhcp addresses from the netgear. at the moment only about 10 users. all the equipment we have

consists of apc netshelter vx rack, mac g4(1u), another mac in a custom 4U enclosure, a 2U dell poweredge 2850, a 2U dual opteron 265 linux machine, the cisco 3550, a 1U ups dont remember what size it is. and the little netgear just sitting on top of all of it.
 
geist said:
so the pix is just a firewall? its not a router too? do i need a router? the way things are setup right now are really screwed up, our wan comes in and plugs into the 3550 then gets plugged into the netgear which is plugged back into the 3550 and then all of our workstations are plugged intot he 3550 which get dhcp addresses from the netgear. at the moment only about 10 users. all the equipment we have

consists of apc netshelter vx rack, mac g4(1u), another mac in a custom 4U enclosure, a 2U dell poweredge 2850, a 2U dual opteron 265 linux machine, the cisco 3550, a 1U ups dont remember what size it is. and the little netgear just sitting on top of all of it.

You mentioned IP phones so let me guess, based on the way you described the netowrk configuration, you have IP Comm service through an HIPC (Hosted Ip Communications) provider??
 
yup our isp is a company called knology, and since we wanted the ip phones we were told we had to purchase the the 3550.
 
geist said:
yup our isp is a company called knology, and since we wanted the ip phones we were told we had to purchase the the 3550.

And they also told you the IP Phones needed to reside outside of the firewall on a seperate VLAN because they run MGCP and have issues accessing the soft switches through a firewall???

Basically, your topology is correct, the only question for you would be, do you realy need another firewall, correct?
 
so its normal to have a switch connected to the wan and then back into your firewall? i guess what i thinking is router/firewall connects to lan and then the switches connect to that. also do cisco routers do dchp. we have 4 static ip addresses and it would be nice if we could NAT all four them..right now just one of them is fed into the netgear and then it deals out dhcp addresses to the workstations. and then 3 of the ports on the switch are the rest of our external static ips.
 
geist said:
so its normal to have a switch connected to the wan and then back into your firewall? i guess what i thinking is router/firewall connects to lan and then the switches connect to that. also do cisco routers do dchp. we have 4 static ip addresses and it would be nice if we could NAT all four them..right now just one of them is fed into the netgear and then it deals out dhcp addresses to the workstations. and then 3 of the ports on the switch are the rest of our external static ips.

For the vast majority of folks that would not be normal, but based on your situation it would be normal. Yes, Cisco routers/firewalls can provide DHCP addresses to clients. Also, with four public addresses you will be able to use them all on one PIX or router and configure them any way you want...
 
If you only have 10 users you definitly do not need a router regardless of what the cisco fanatics have to say. You also don't in any way need a cisco pix firewall. If you need proof just compare the prices of any cisco product to any similar product from another company.

I would suggest getting a 24 port switch from HP or 3com or any of the other buisness grade companies. I know for a fact that an HP Procurve series switch can do all the same port forwarding and port monitoring stuff. If you feel that you need a firewall any old PC can be turned into a smoothwall box. Smoothwall is a free linux based firewall that take puts out a nice webpage for you to do config and monitoring once it's installed.

I have about 300 clients running through a 400mhz P2 box running smoothwall at work and I have absolutly no problems. I should meet your needs very well for the cost of an old PC. Or you could buy a cisco pix firewall which is actually just a 400hmz processor and some network cards in a very pretty box for several thoulsand dollars.

edit: Smoothwall also does DHCP you just have to turn it on in the config.

I'm not trying to start a flamewar in any way but I just got done dealing with upgrading network hardware at work and I found that although cisco has a very good reputation and they make great products their costs are very unreasonable and their support fee's are very high.
 
ethos747474nikon8989 said:
If you only have 10 users you definitly do not need a router regardless of what the cisco fanatics have to say. You also don't in any way need a cisco pix firewall. If you need proof just compare the prices of any cisco product to any similar product from another company.

I would suggest getting a 24 port switch from HP or 3com or any of the other buisness grade companies. I know for a fact that an HP Procurve series switch can do all the same port forwarding and port monitoring stuff. If you feel that you need a firewall any old PC can be turned into a smoothwall box. Smoothwall is a free linux based firewall that take puts out a nice webpage for you to do config and monitoring once it's installed.

I have about 300 clients running through a 400mhz P2 box running smoothwall at work and I have absolutly no problems. I should meet your needs very well for the cost of an old PC. Or you could buy a cisco pix firewall which is actually just a 400hmz processor and some network cards in a very pretty box for several thoulsand dollars.

edit: Smoothwall also does DHCP you just have to turn it on in the config.

I'm not trying to start a flamewar in any way but I just got done dealing with upgrading network hardware at work and I found that although cisco has a very good reputation and they make great products their costs are very unreasonable and their support fee's are very high.

1) PIX's for small companies do not cost several thousands of dollars. A 501 or 506E can be had for $595 and $1395 respectively. That is also MSRP so it's on the high end.

2) SMARTnet and Cisco TAC, when you have a problem with the PIX it gets resolved, PERIOD. Why would you throw together an OLD PC, especially for a business, when you have the budget to purchase a business grade solution?? That is not a very good business decision...

3) He already said he had a Cisco 3550 switch, why would you suggest purchasing another one when we already determined he does not need one? He simply needs to add a more functional firewall to gain some more advanced features...

4) Their support fee's are nowhere near high considering they have some of the best support in the industry. I can get 24x7x4 support on a PIX for ~$120 a year. That is a bargain as far as insurance policies are concerned...

P.S. - If you are connecting a private network to the Internet, you MUST have a router and what you suggested as far as a switch goes would be considered a Layer3 switch which guess what.... IS A ROUTER... You may or may not be trying to help this guy out, but please try to provide correct information instead of crapping on the Cisco PIX because it cost more than a Smoothwall. Price is not the only factor when purchasing IT solutions for a business...
 
so then what do you think just use the pix and keep the setup the same or should i go for a router that has firewall built into it. basically i want to get rid of the netgear. i dont like them i have had one at home and nad nothing but problems with it, and at work its been the same...every once in a while we have to reboot it to get it to work properly.

so im trying to find out what the best solution is.
 
If you go with the PIX you will be fine, it has all of the routing functionality you would ever need for what you want to do...

Think of it as a direct replacement for your Netgear...
 
Indeed, the PIX has the functionality to route, but as you would not like switch routing, I don't want my firewall doing it either. 2600XM, 2800, and the 871 series routers do indeed have firewall hardware acceleration. UNless you are adding applicaiton layer (NBAR or CBAC) dynamic firewall protection you would never have a difficulty (in processing) using them as your firewall. The 871 series even has hardware support for processing inbound intrusion prevention processing. The PIX 501 has crap for throughput also.
 
Back
Top