Re: PIX 506e



In article <1141094611.318423.277870@xxxxxxxxxxxxxxxxxxxxxxxxxxxx>,
starman7@xxxxxxxxxxx <starman7@xxxxxxxxxxx> wrote:
I have a few questions before buying the 506e:

Can I configure this via a web interface, or must I use the CLI (and
commands) to do the above config; or can I generate the config via some
software program?

The standard warning I give here is that if you think you might
be asking questions configuring PIX here, then you had best learn
the CLI (possibly in addition to the GUI.) The answers here are
almost always in terms of the CLI. The people who answer questions
here generally don't have time to figure out and write down the
long sequence of menu items and drop-boxes that are needed in
the GUI to configure things that take only a few lines in the CLI.


The reason we are wanting a firewall (aside from being able to control
it ourself, and for the other benefits) is to see if we can gain better
insight into some network problems we are having (mainly spikes in
bandwidth, in and out, and it maxing it out), does the 506e have robust
logging, to help determine the source and destination addresses/ports
of the problematic traffic?

If that is your main purpose then just configure your 1600 to
SPAN or RSPAN the traffic off to a computer that is running a
network analysis program. PIX are not designed to be able to
correlate traffic spikes and particular traffic. You can do it
to some extent, but the PIX is designed for security not for
volume control.
.



Relevant Pages

  • Re: PIX 501 Verizon Infospeed DSL
    ... When you connect PIX 501 you cannot get to internet - correct? ... PIX 501 PPPOE config is incorrect or incomplete ... See Cisco doc "Configuring the PPPoE Client on a Cisco Secure PIX ... !--- Define the VPDN group that you use for PPPoE. ...
    (comp.dcom.sys.cisco)
  • Re: PIX 501 Verizon Infospeed DSL
    ... When you connect PIX 501 you cannot get to internet - correct? ... PIX 501 PPPOE config is incorrect or incomplete ... See Cisco doc "Configuring the PPPoE Client on a Cisco Secure PIX ... !--- Define the VPDN group that you use for PPPoE. ...
    (comp.dcom.sys.cisco)
  • Re: have PIX with VPN, need to obtain isakmp key
    ... Maybe if we use TFTP to copy the startup config to a server that will ... possible we need to get the existing isakmp key from the PIX. ... You've not clearly stated whether you are referring to the RSA keys used ... referring to a pre-shared key. ...
    (comp.dcom.sys.cisco)
  • Re: [fw-wiz] Pix rulebase/policy analysis
    ... You make very good points regarding the text editor, ... you have applied to the Pix. ... Personally I would rather the config be self documenting. ... I prefer the syntax validation of configuring at the command line rather ...
    (Firewall-Wizards)
  • Re: [Full-Disclosure] PIX vs CheckPoint
    ... I use both PIX and Checkpoint, and have used Checkpoint since 3.0b. ... where the CP GUI presents the config in very concise/intuitive matter. ... CP rules for multiple firewall management. ...
    (Full-Disclosure)