Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

You may experience some slow load times, errors, and slight inconsistencies. We ask for your patience as we finalize the launch. Thank you.

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started.

New Member

PIX515E adding another T1

We are using a PIX515E with just one router connected. We're installing PACS and Philips implementation specialists say they will install a new T1 line plus router which will be solely used for backup of PACS images.

Here's my dilemma: will I need to use another interface on the PIX to connect the router? How will I configure the PIX so that data going to that T1 goes only out that interface as it will need to be encrypted also?

  • Other Security Subjects
4 REPLIES
New Member

Re: PIX515E adding another T1

Hi,

Well this will depend on how you want to design and what are your security requirements. But my suggestion will be to use a different interface to connect to this new link if you are not terminating tunnel on the pix. As they will have a network which can be routed off this interface to their backup devices.

But if you can terminate the tunnel on the pix or if you donot have an interface to spare (so no other option) then you can use the outside interface as well for tunnel end point. It will be good if you provide details of the design requirements and security requirements.

New Member

Re: PIX515E adding another T1

Our current config is for 1 T1 line connected enables interfaces are:

interface ethernet0 auto

interface ethernet1 auto

interfaces 2 - 5 shutdown

If I enable interface 2 and connect the router to that interface, would I then create a VPN specifying that VPN is to use interface 2?

Re: PIX515E adding another T1

basically you have 2 options:

1.- Use a second physical interface ( easiest way to do it in your scenario ). You will need to terminate a VPN on this interface for the PACS that you are talking about.

2.- Use one physical interface and two subinterfaces ( if you software suports it). This will require you to have a spare switch for creating 2 VLANs ( one per ISP link ). Connect the routers to the switch on their respective VLANs. Configure one interface on the PIX as trunk and connected to a trunk port on the swtich. Create subinterfaces on the PIX and allocate them to the respective VLAN.

I hope it helps ... please rte it if it does !!!.

New Member

Re: PIX515E adding another T1

So, if I use the following commands to enable intf 2 & 3:

interface ethernet2 auto

interface ethernet3 auto

nameif ethernet2 PhilOut security 0

nameif ethernet3 Philin security 100

ip address Philout 198.110.86.11

ip address Philin 192.168.125.100

Can I then create a VPN utilizing those two interfaces?

139
Views
0
Helpful
4
Replies