Configuring the PIX as a Gateway

The PIX firewall comes standard with two switchable 10/100 Megabit Ethernet cards, a serial console port, a failover control card, some required cabling and mounting parts, and possibly a secure encryption card, depending on the bundle purchased. In this section we will set up a PIX unit right out of the box, configure it for basic operation, and set up an average firewall. Beyond that, we will illustrate the setup of multiple PIX units so that they may link to one another across the Internet, thus creating a VPN.

In this section, we show you how to connect to the PIX so you can configure it, how to set up your firewall on the PIX, and how to do some initial testing. Configuration of the PIX doesn’t affect configuration of any other hosts on the inner or outer networks, which you can still set up using traditional rules. The configuration examples in this chapter were set up using the 4.1.6 version of the PIX operating software.

Connecting to the PIX

Example 9-1 shows the PIX boot screen, which is sent to the console port when the unit powers on. A serial console cable, supplied with the unit, must be attached to a personal computer, and the terminal software must be configured as follows before any commands may be input into the system:

  • 9600 baud

  • 8 bits, no parity, 1 stop bit

To confirm that the connections are made properly and that the terminal software is set up right, simply booting the PIX firewall should produce the output seen in Example 9-1 ...

Get Virtual Private Networks, Second Edition now with O’Reilly online learning.

O’Reilly members experience live online training, plus books, videos, and digital content from 200+ publishers.