Chapter 8 Configuring a Simple Firewall

Figure 8-1shows a network deployment using PPPoE or PPPoA with NAT and a firewall.

Figure 8-1 Router with Firewall Configured

2

4

7

3

5

1

6

121781

1

Multiple networked devices—Desktops, laptop PCs, switches

 

 

2

Fast Ethernet LAN interface (the inside interface for NAT)

 

 

3

PPPoE or PPPoA client and firewall implementation—Cisco Secure Router 520 Series router

 

 

4

Point at which NAT occurs

 

 

5

Protected network

 

 

6

Unprotected network

 

 

7

Fast Ethernet or ATM WAN interface (the outside interface for NAT)

 

 

In the configuration example that follows, the firewall is applied to the outside WAN interface (FE4) and protects the Fast Ethernet LAN on FE0 by filtering and inspecting all traffic entering the router on the Fast Ethernet WAN interface FE4. Note that in this example, the network traffic originating from the corporate network, network address 10.1.1.0, is considered safe traffic and is not filtered.

Configuration Tasks

Perform the following tasks to configure this network scenario:

Configure Access Lists

Configure Inspection Rules

Apply Access Lists and Inspection Rules to Interfaces

A configuration example that shows the results of these configuration tasks is provided in the “Configuration Example” section on page 8-5.

Cisco Secure Router 520 Series Software Configuration Guide

8-2

OL-14210-01

 

 

Page 90
Image 90
Cisco Systems 520 series manual Fast Ethernet LAN interface the inside interface for NAT