Section 4.0: PIX Configuration

4.1. Basic PIX Configuration

  1. Configure the PIX IP address as shown in Figure 7-1.

  2. Configure static NAT translation for the AAA server with the IP addresses shown in Figure 7-1. Configure ACL accordingly.

  3. Configure RIP for R1 and R2 as per Section 2.3 with clear-text authentication.

  4. Configure a static default route on PIX to R2.

4.2. Advanced PIX Configuration

  1. Configure a filter to deny Java applets and ActiveX controls that return to the AAA server from an outbound HTTP connection:

    								filter activex 80 172.16.1.3 255.255.255.255 0.0.0.0 0.0.0.0
    								filter java 80 172.16.1.3 255.255.255.255 0.0.0.0 0.0.0.0
    							
  2. Configure a filter for all users except the AAA server to prevent outbound users from accessing World Wide Web URLs based ...

Get CCIE Security Practice Labs now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.