Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Community Member

Pix Placement

My GW router is getting many IP spoofing and other attempts.My internet traffic suddenly goes up without any reason.

To tackle with i have get a pix 501.What must be the physical placement of the firewall. Should i place it behind my internet router (b/w internet router and LAN) or even before internet router to avoid unwanted traffic ?

4 REPLIES

Re: Pix Placement

behind your internet router. by default the PIX will block any inbound connection and permit ip outbound.

internet GW --- PIX501-----LAN

Francisco

Community Member

Re: Pix Placement

Ok..

My internet bandwidth is being dropped on my router. if i use pix behind the router can i stop the illegal b/w usage ?

Please also qoute some idea of pix and router optimization config to avoid and save bandwidth usage

THANKS

Re: Pix Placement

munawar,

firstly, you will need to find out what is utilizing your internet bandwidth before you can stop.

Re: Pix Placement

In addition to Francisco's post, you may need to do additional filtering in your router facing ISP/Internet, even by placing firewall it is recommended to implement some additional security in your edge router.

Go over this link which provides anti-spoofing acls .

http://www.cisco.com/en/US/tech/tk648/tk361/technologies_white_paper09186a00801afc76.shtml

Rgds

-Jorge

181
Views
0
Helpful
4
Replies
CreatePlease to create content