<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Deploying FTD Data Center Firewall in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/deploying-ftd-data-center-firewall/m-p/4075951#M1069591</link>
    <description>&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;If you can provide the useful links, that would be very grateful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 28 Apr 2020 22:24:15 GMT</pubDate>
    <dc:creator>techno.it</dc:creator>
    <dc:date>2020-04-28T22:24:15Z</dc:date>
    <item>
      <title>Deploying FTD Data Center Firewall</title>
      <link>https://community.cisco.com/t5/network-security/deploying-ftd-data-center-firewall/m-p/4074461#M1069523</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We are working on a solution o&lt;/SPAN&gt;&lt;SPAN&gt;ver deployment of Cisco FTD,&amp;nbsp; F5 Load balancers and Nexus 9K Switches ( DC Core) with following interest:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;- To control and inspect the traffic from between users and servers.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- To isolate the&amp;nbsp; public facing web servers sourcing from internet. Example DMZ&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;- The purpose of adding FTD is to integrate with AMP Cloud. We will be deploying AMP for endpoint and servers&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Current deployment&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; PAN-FW1&amp;nbsp; &amp;nbsp; &amp;nbsp; PAN-FW2&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; |&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; |&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; |&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; |&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; |&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; |&amp;nbsp;&lt;/P&gt;&lt;P&gt;Servers ----&amp;nbsp; TOR Switches --- 6807 ( Core Network) --- Access Layer ( users)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;At the moment we have two internet boundry firewall handling ingress/egress NAT, VPN connections&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;So I am looking for advise validated design and suggestions where to install the new firewalls pairs, F5 and DC Core in the path as mentioned above.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would appreciate any feedback and suggestions&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I put together a fairly current&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Apr 2020 21:01:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deploying-ftd-data-center-firewall/m-p/4074461#M1069523</guid>
      <dc:creator>techno.it</dc:creator>
      <dc:date>2020-04-26T21:01:24Z</dc:date>
    </item>
    <item>
      <title>Re: Deploying FTD Data Center Firewall</title>
      <link>https://community.cisco.com/t5/network-security/deploying-ftd-data-center-firewall/m-p/4074463#M1069525</link>
      <description>&lt;P&gt;You can connect Nexus switches to your Core Switch&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Core -- Nexus---FW --LB--Servers&amp;nbsp; high level.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Apr 2020 21:11:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deploying-ftd-data-center-firewall/m-p/4074463#M1069525</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-04-26T21:11:07Z</dc:date>
    </item>
    <item>
      <title>Re: Deploying FTD Data Center Firewall</title>
      <link>https://community.cisco.com/t5/network-security/deploying-ftd-data-center-firewall/m-p/4074465#M1069526</link>
      <description>&lt;P&gt;Thanks Balaji. I have couple of concerns here.&lt;/P&gt;&lt;P&gt;- In such deployment, Core would have default routes pointing to Nexus then FW will control the access to servers.&lt;/P&gt;&lt;P&gt;What about the internet traffic from users and servers ?&lt;/P&gt;&lt;P&gt;- Is this design for DMZ servers only ? or Internal Servers as well ?&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Core -- Nexus---FW --LB--Servers&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- Traffic originating from internet to Web servers will hit Internet Boundtry firewall and how it would traverse to DMZ servers&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- I just need to know required traffic flow (direction, south-north or east-west), pattern.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Apr 2020 21:20:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deploying-ftd-data-center-firewall/m-p/4074465#M1069526</guid>
      <dc:creator>techno.it</dc:creator>
      <dc:date>2020-04-26T21:20:48Z</dc:date>
    </item>
    <item>
      <title>Re: Deploying FTD Data Center Firewall</title>
      <link>https://community.cisco.com/t5/network-security/deploying-ftd-data-center-firewall/m-p/4075181#M1069554</link>
      <description>&lt;P&gt;For internal users to DC Server that design works.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you looking External Access to Internal you need to create a DMZ here. with diferent Context in FW.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So inernal users use 1 Context, External access used in Different Context.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Most of the time its hosting kind setup, Traffic North to south (this is your DMZ Setup)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;East-West Traffic should have common transit point with Dynamic routes shoudl consider, so the traffic will not go to north and come back again, waste of bandwidth.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Look at some CVD guides of DC Design should help, again this all depends on how you build and expertise to fix things, Dynamic routing vs Static routing. Every design has pros and cons.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2020 22:16:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deploying-ftd-data-center-firewall/m-p/4075181#M1069554</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-04-27T22:16:25Z</dc:date>
    </item>
    <item>
      <title>Re: Deploying FTD Data Center Firewall</title>
      <link>https://community.cisco.com/t5/network-security/deploying-ftd-data-center-firewall/m-p/4075951#M1069591</link>
      <description>&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;If you can provide the useful links, that would be very grateful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2020 22:24:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deploying-ftd-data-center-firewall/m-p/4075951#M1069591</guid>
      <dc:creator>techno.it</dc:creator>
      <dc:date>2020-04-28T22:24:15Z</dc:date>
    </item>
    <item>
      <title>Re: Deploying FTD Data Center Firewall</title>
      <link>https://community.cisco.com/t5/network-security/deploying-ftd-data-center-firewall/m-p/4076496#M1069635</link>
      <description>&lt;P&gt;here is some design guides for reference :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/solutions/enterprise/data-center-designs-data-center-networking/index.html" target="_blank"&gt;https://www.cisco.com/c/en/us/solutions/enterprise/data-center-designs-data-center-networking/index.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you are not sure, i would suggest to contact local SE or cisco partner help you, so your investment will be protect with small profession costing.,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2020 16:45:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deploying-ftd-data-center-firewall/m-p/4076496#M1069635</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-04-29T16:45:05Z</dc:date>
    </item>
    <item>
      <title>Re: Deploying FTD Data Center Firewall</title>
      <link>https://community.cisco.com/t5/network-security/deploying-ftd-data-center-firewall/m-p/4076592#M1069654</link>
      <description>&lt;P&gt;Thank you Balaji. Great help from best professionals&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2020 18:41:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deploying-ftd-data-center-firewall/m-p/4076592#M1069654</guid>
      <dc:creator>techno.it</dc:creator>
      <dc:date>2020-04-29T18:41:46Z</dc:date>
    </item>
  </channel>
</rss>

