Great Circle Associates Firewalls
(November 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Cisco's PIX firewall
From: Irwin Lazar <lazar @ netevolve . com>
Date: Mon, 25 Nov 1996 13:53:58 -0500
To: "Zak Alameddine" <zaka @ tiac . net>
Cc: firewalls @ greatcircle . com

Zak,
We have used the PIX for several clients with varying size networks.  

The biggest advantage to the PIX is that you can use a private addressing
scheme on your network.  This allows you to create a meaningful IP
addressing scheme.  For example, you can designate the second octet to
match the OSPF area the address is used in.  (i.e 10.3.0.0 for area 3,
10.4.0.0 for area 4 and so on).  Another advantage to private addressing is
that you never have to worry about renumbering your network due to changing
ISP's or anything like that.

As far as the security aspects of PIX, it basically hides your entire
network from the outside world.  Unless your PIX is corrupted, hosts
outside of your network can never directly connect to hosts within your
network since private addresses are not routed on the Internet.  The
downside to the PIX is that it has limited access-list ability and it's not
very user friendly.

You also might want to check out version 11.2 of the Cisco IOS, which has
PIX functionality built in.  It also has support for traditional IP and
extended IP access lists.

Good luck,
Irwin Lazar
Network Evolutions, Inc.
http://www.netevolve.com

At 11:32 AM 11/25/96 -0500, you wrote:
>Question:
>
>Has anyone used Cisco's PIX firewall? If anyone has, what are the 
>advantages/disadvantages of using it? 
>
>I would appreciate any input. Thanks a lot.
>
>Zak Alameddine
>
>



Follow-Ups:
Indexed By Date Previous: RE: Redundant FW-1's
From: Russ <Russ . Cooper @ RC . on . ca>
Next: Re: Cisco's PIX firewall
From: mitch @ qualcomm . com (Mark Mitchiner)
Indexed By Thread Previous: Cisco's PIX firewall
From: "Zak Alameddine" <zaka @ tiac . net>
Next: Re: Cisco's PIX firewall
From: Blast <blast @ worldbit . com>

Google
 
Search Internet Search www.greatcircle.com