<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ASA 5508-X network topology placement in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-network-topology/m-p/3220741#M1064892</link>
    <description>&lt;P&gt;I would consider two more options:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Place both outside interfaces of the router and ASA onto the internet and the router inside interface in an ASA-DMZ&lt;/LI&gt;
&lt;LI&gt;Place the router on a stick in an ASA-DMZ&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 22 Nov 2017 08:41:03 GMT</pubDate>
    <dc:creator>Karsten Iwen</dc:creator>
    <dc:date>2017-11-22T08:41:03Z</dc:date>
    <item>
      <title>Cisco ASA network topology</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-network-topology/m-p/3220715#M1064891</link>
      <description>&lt;P&gt;Trying to figure out the best placement for a Cisco ASA 5508-X in our network that already has a Cisco 2900 router in place for the edge WAN and some internal Cisco Catalyst core and distro switches.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In a dilemma whether we should place the ASA in front of the router or behind it? There has been no documented best practice so based on all your experience which works well and is best practice in your environment?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm an advocate in leveraging each appliance's or device's key strengths so was thinking of letting the router do what it does best, which is routing and GRE tunnels, and leave the ACLs/filtering/IDS/IPS/IPsec tunneling/etc. of course in the ASA. But ideally where do we NAT (router vs ASA) on either of the options below?...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Option 1. (internal) -- (Cisco ASA 5508-X) -- (Cisco Router 2900) -- [internet]&lt;/P&gt;
&lt;P&gt;Option 2. (internal) -- (Cisco Router 2900) -- (Cisco ASA 5508-X) -- [internet]&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks and would appreciate feedback. Would also appreciate sample configurations to supplement if any.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:48:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-network-topology/m-p/3220715#M1064891</guid>
      <dc:creator>dereksters</dc:creator>
      <dc:date>2020-02-21T14:48:47Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA 5508-X network topology placement</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-network-topology/m-p/3220741#M1064892</link>
      <description>&lt;P&gt;I would consider two more options:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Place both outside interfaces of the router and ASA onto the internet and the router inside interface in an ASA-DMZ&lt;/LI&gt;
&lt;LI&gt;Place the router on a stick in an ASA-DMZ&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2017 08:41:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-network-topology/m-p/3220741#M1064892</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2017-11-22T08:41:03Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA 5508-X network topology placement</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-network-topology/m-p/3220754#M1064893</link>
      <description>&lt;P&gt;Hi Karsten, do you mind putting that out in a diagram like what I did with my post? Also, any reason why I'd want the router and ASA outside interfaces facing out the WAN both? Thing is if I do that though I will have to put a layer 2 switch before them to split out the WAN connection. Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2017 09:14:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-network-topology/m-p/3220754#M1064893</guid>
      <dc:creator>dereksters</dc:creator>
      <dc:date>2017-11-22T09:14:59Z</dc:date>
    </item>
  </channel>
</rss>

