cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
302
Views
0
Helpful
2
Replies

InternVLAN rules on PIX506

alig.norbert
Level 4
Level 4

Hi all,

I need to build up a DMZ with a PIX506. My idea is to make a trunk between PIX and switch, assign a VLAN for the DMZ.

Mi question is, can PIX506 handle firewall-rules between the VLAN's (internal <-> dmz)?

Thank's,

Norbert

1 Accepted Solution

Accepted Solutions

Jon Marshall
Hall of Fame
Hall of Fame

Norbert

Not sure what you are asking here. The 506E supports up to 2 vlans on an interface so you can do what you want. Each vlan interface is treated as a physically separate interface in terms of security levels/access-lists etc.

So if you have an inside and a DMZ on the same interface you can apply separate access-lists to each interface.

Does this answer your question ?

Jon

View solution in original post

2 Replies 2

Jon Marshall
Hall of Fame
Hall of Fame

Norbert

Not sure what you are asking here. The 506E supports up to 2 vlans on an interface so you can do what you want. Each vlan interface is treated as a physically separate interface in terms of security levels/access-lists etc.

So if you have an inside and a DMZ on the same interface you can apply separate access-lists to each interface.

Does this answer your question ?

Jon

Jon

Thank's for the answer.

Yes I want to control the traffic between DMZ (VLAN-xx)<-> inside (VLAN-yy) over the PIX.

Greets,

Norbert