Good Information Articles |
Stop Parking Domain Names Develop Your Domain Names |
|||||||
How to secure your small business with a PIX firewall
One of the more popular firewall products for the small business market is the Cisco PIX 501. Out of the box it requires just a few configuration entries and you are up and running. In this guide, we will walk through the steps for configuring your brand new pix at the network edge. This guide is written for the user who has no knowledge of the PIX firewall. As such, it is not a treatise on network security, but a quick, by-the numbers guide to configuring a PIX firewall with as little jargon as possible. We are assuming that you have an internet connection with at least one static IP address. While the PIX can easily handle a dynamic IP address (that is the default configuration), you won't be able to easily configure remote access, VPNs, Mail, or web servers without a static IP address. Your PIX should have come with an AC adapter, a yellow CAT 5 cable, an orange CAT5 cable and a flat, (typically) baby blue cable with a 9-pin serial connector on one end and an RJ-45 plug on the other. The yellow CAT5 cable is a standard Ethernet cable and is used to connect your pc or server to the 4-port Ethernet switch built into the PIX. The Orange CAT5 cable is a cross-over cable and may be required to connect the outside interface of the PIX to your ISP's router (if your PC's or workstations are plugged into a Cisco switch inside the network, you will also require a cross-over cable for connecting to one of the switch ports on the PIX). What we are going to use for our configuration is the baby blue rollover cable. Insert the serial jack into one of the serial ports on the back of the PC or laptop you will be using to configure the PIX. Then, insert the RJ-45 plug into the port on the back of the PIX labeled "console." Windows has a built in application that is used for (among other things) configuring serial devices. Using the start menu, go to Start > Programs > Accessories > Communications > Hyper Terminal. Choose the Hyper Terminal application. You may get a dialog box asking if you'd like to make Hyper Terminal your default telnet application. Unless you have a preference, go ahead and choose yes. Then you will be asked for the area code from which you are dialing, although it isn't applicable here, the program still wants to know, so fill it in and click 'next' or 'ok.' You can call the connection anything you'd like; in this example we'll use PIX. Click 'ok' to move on. Next, we'll be asked to enter the details for the phone number we'd like to dial. Since we aren't dialing a phone number, use the drop-down selector at the bottom of the box to choose COM1 or COM2 (whichever is applicable). If you have no idea which one is which, you may need to try it both ways. Now, you will be expected to tell the application some specifics about the port settings so that it can effectively communicate with the PIX. Luckily, it isn't too complex, just remember 9600, 8, none, and 1. Enter these settings into the drop down selectors of the box on your screen. Now we are ready to set up the PIX. Insert the power cable and you will be greeted with the startup monologue (it's not a dialog in this case; it's just informing you of what is occurring). Then, you will be greeted with a screen that asks if you'd like to program the PIX using interactive prompts. For the purpose of this exercise, type no and click 'enter'. You will now get a prompt that looks like this: The prompt has changed to a hash mark: Your prompt will now look like this: The first thing we want to do is give your pix a host name. The PIX command syntax is: Thus, to set the hostname we will enter: Now, the domain name; it's alright if you don't have a domain set up on your network, you can call it whatever you like. However, give some thought to whether a domain might be a possibility at some point and plan your naming scheme appropriately. As you can see from the configuration above, the ethernet0 interface is the outside interface, with a security setting of 0, while ethernet1 is the inside interface with a security setting of 100. Additionally, you can see that the interfaces are shutdown. All we need do to bring them up is enter the speed at which they should operate. As they are Ethernet interfaces, any software version after 6.3(3) will take 100full, prior to that, use 10full. pixfirewall(config)# interface ethernet0 100full Now to assign an address to the inside and outside interfaces; the ip address command sets the ip address of an interface. The syntax is as follows: An example might be as follows: Then the inside IP address A brief word about IP addressing is in order here. One way that is used to conserve public IP addresses is through the use of non-routable IP addressing blocks specified in RFC 1597. You may sometimes hear them referred to as "private" IP addresses, which is fine, but not quite technically accurate. There are three different blocks to choose from: as long as your internal network's IP addresses are all within one of those blocks of address space, you will not need to introduce the complexity of routing within your LAN. An example scheme for those who are not familiar is shown below: It is very important now to add a default route to the PIX configuration. Another term for default route is the "default gateway." You need to tell the PIX that if it receives traffic destined for a network that isn't directly connected, it should send it to the connected ISP router. Your ISP should have given you the IP address of your default gateway when you received your setup information. Here is the syntax: For example To password protect your PIX in order to prevent unauthorized access, use something that is secure and hard to guess. Try to stay away from the names of spouses, children, pets, birthdays or other easily guessed variable. Whenever possible, use a combination of letters and numbers. The syntax is as follows (but please don't use cisco as your actual password) Now that your PIX has been given a basic configuration, you should be able to access the internet, while preventing unauthorized access to your resources. Ron Jones is the Founder and President of The Fulcrum Technology Group, Inc. www.fulcrumtechnologygroup.com Located just North of Atlanta, this consulting firm specializes in business technology solutions that will enable you to maintain a competitive advantage by increasing productivity, improving reliability and reducing expenses.
Other Article Sites findabook.com moneycd.info a-mortgage.info
about-lemon-laws.info aboutstudentloans.info |
MORE ARTICLES: Family Circus - Make Time For Family With An Internet Business Sometimes, it seems like you don?t have a full 24 hours in a day. Between work, family, and sleep, there is no time for anything else. You never seem to have five minutes to relax, and on days when work requires overtime, you lose time with your family. In fact, it seems you never spend quality time with your children anymore. One way to get your life back under your control and manage time better is to start your own internet business. With an online business opportunity, you can decrease your work hours overall, as well as become more flexible and available for your family.
SoGoNow.com -- Home of the Best Travel Article Written for the Internet in 2006
Internet Home Based Business : Legitimate Work at Home Jobs Opportunities and Advantages
Home Internet Business Opportunities: Reinvent Your Family
New Home Based Travel Businesses and Training Available for Retirees and Work-At-Home Parents
Sales of Children's Travel Bed Soar as Summer Travel Hits
Children's Home Society & Family Services Receives Reaccreditation to Once Again Facilitate Adoptions in Russia
Home Based Internet Marketing Business - Staying Organized In Your Home Office
Travel Insurance When Pregnant Or Traveling With Children
Internet Marketing Business - Your Home Based Internet Marketing Business and the Freedom Attached with it
Business & Family Safety and Health Rating
Making Time For Your Family and a New Internet Home Business
The Best Internet Connection For A Top Home Internet Business
Work At Home Internet Home Business Opportunity
Work From Home - Online Resource Center for Home Based Online Jobs and Internet Based Business
|
|||||||
| Develop Your Domain Names | Site Map | Home | ||||||||