<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is the network over designed? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/is-the-network-over-designed/m-p/4439721#M1082512</link>
    <description>&lt;P&gt;Also, forgot to mention, whether you use VRFs pr not depends on your design. If you are not doing any routing on the L3 switch then there is no need for VRF so just trunk the VLANs to the firewall.&lt;/P&gt;
&lt;P&gt;I also agree with Leo that with regards to who you choose to do the design and implementation. The cheapest provider on design and implementation often ends up being the most expensive in the long run.&lt;/P&gt;</description>
    <pubDate>Tue, 27 Jul 2021 15:49:12 GMT</pubDate>
    <dc:creator>Marius Gunnerud</dc:creator>
    <dc:date>2021-07-27T15:49:12Z</dc:date>
    <item>
      <title>Is the network over designed?</title>
      <link>https://community.cisco.com/t5/network-security/is-the-network-over-designed/m-p/4439091#M1082478</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;The uploaded JPG is a summary layout that reflects the network design provided by a contractor for our 6 floor new building. I feel the network is over designed. My question is do I need this number of firewalls? We did ask the LANs traffic to be segregated as they carry different traffic for different purposes?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="LAN.JPG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/126172i0C31977F9B35D84D/image-size/large?v=v2&amp;amp;px=999" role="button" title="LAN.JPG" alt="LAN.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jul 2021 19:52:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/is-the-network-over-designed/m-p/4439091#M1082478</guid>
      <dc:creator>abdullah.abdulhafid</dc:creator>
      <dc:date>2021-07-26T19:52:18Z</dc:date>
    </item>
    <item>
      <title>Re: Is the network over designed?</title>
      <link>https://community.cisco.com/t5/network-security/is-the-network-over-designed/m-p/4439101#M1082481</link>
      <description>&lt;P&gt;I agree that this is overkill with firewalls.&amp;nbsp; You would only need the following:&lt;/P&gt;
&lt;P&gt;- a pair of firewalls in HA setup&lt;/P&gt;
&lt;P&gt;- Etherchannel configuration between ASAs and the 3650 switches.&amp;nbsp; Configure subinterfaces on the portchannel for the various LANs&lt;/P&gt;
&lt;P&gt;- Configure access rules restricting access between the LANs on the sub interfaces&lt;/P&gt;
&lt;P&gt;- ***no L3 routing on the switches***. If L3 is required on the switches use VRFs&lt;/P&gt;
&lt;P&gt;I do not know what your requirements are, but I would also suggest looking into using FTD devices and not ASAs.&amp;nbsp; I would also suggest using Firepower software instead of ASA with the threat license as a minimum.&amp;nbsp; This is because Firepower will provide IPS while the ASA does not.&amp;nbsp; It can also do almost everything the ASA can do.&lt;/P&gt;
&lt;P&gt;If Firepower software is not an option, the FTD devices can also run ASA software.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jul 2021 20:17:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/is-the-network-over-designed/m-p/4439101#M1082481</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2021-07-26T20:17:38Z</dc:date>
    </item>
    <item>
      <title>Re: Is the network over designed?</title>
      <link>https://community.cisco.com/t5/network-security/is-the-network-over-designed/m-p/4439148#M1082483</link>
      <description>&lt;P&gt;Where did the contractor get this design from because it looks like one from a PacketTracer design.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Without knowing the criteria of the network it is hard to determine if the FW are overkills.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jul 2021 23:00:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/is-the-network-over-designed/m-p/4439148#M1082483</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2021-07-26T23:00:25Z</dc:date>
    </item>
    <item>
      <title>Re: Is the network over designed?</title>
      <link>https://community.cisco.com/t5/network-security/is-the-network-over-designed/m-p/4439416#M1082489</link>
      <description>&lt;P&gt;It looks like homework to me. No reputable contractor anywhere in the world would propose a design with 6 out of 7 devices being past end-of-sales.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jul 2021 08:34:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/is-the-network-over-designed/m-p/4439416#M1082489</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-07-27T08:34:14Z</dc:date>
    </item>
    <item>
      <title>Re: Is the network over designed?</title>
      <link>https://community.cisco.com/t5/network-security/is-the-network-over-designed/m-p/4439456#M1082493</link>
      <description>&lt;P&gt;Sorry Marvin,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The sketch is done by myself. I do not have the authority to publish the original documents. The LANs in our network represent different security system for example; Fire and Gas system, PA/GA system and etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am worried about the number of firewalls and I need to reduce the cost as long as there is no security breach.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Abdalla&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jul 2021 09:34:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/is-the-network-over-designed/m-p/4439456#M1082493</guid>
      <dc:creator>abdullah.abdulhafid</dc:creator>
      <dc:date>2021-07-27T09:34:12Z</dc:date>
    </item>
    <item>
      <title>Re: Is the network over designed?</title>
      <link>https://community.cisco.com/t5/network-security/is-the-network-over-designed/m-p/4439458#M1082494</link>
      <description>&lt;P&gt;The original documents are not allowed to be uploaded. The layout is done by myself however it describes the real design.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jul 2021 09:35:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/is-the-network-over-designed/m-p/4439458#M1082494</guid>
      <dc:creator>abdullah.abdulhafid</dc:creator>
      <dc:date>2021-07-27T09:35:38Z</dc:date>
    </item>
    <item>
      <title>Re: Is the network over designed?</title>
      <link>https://community.cisco.com/t5/network-security/is-the-network-over-designed/m-p/4439460#M1082495</link>
      <description>&lt;P&gt;Thank you Marius,&lt;/P&gt;&lt;P&gt;Do you suggest to add another layer by using VFRs in case we use L3 features?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jul 2021 09:50:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/is-the-network-over-designed/m-p/4439460#M1082495</guid>
      <dc:creator>abdullah.abdulhafid</dc:creator>
      <dc:date>2021-07-27T09:50:07Z</dc:date>
    </item>
    <item>
      <title>Re: Is the network over designed?</title>
      <link>https://community.cisco.com/t5/network-security/is-the-network-over-designed/m-p/4439479#M1082497</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1227739"&gt;@abdullah.abdulhafid&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;&lt;SPAN&gt;I do not have the authority to publish the original documents. The LANs in our network represent different security system for example; Fire and Gas system, PA/GA system and etc.&lt;/SPAN&gt;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;If this network is deemed as "confidential" then why take un-necessary risk?&lt;/P&gt;
&lt;P&gt;Get a reputable system integrator for confidentiality protection.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jul 2021 10:08:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/is-the-network-over-designed/m-p/4439479#M1082497</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2021-07-27T10:08:46Z</dc:date>
    </item>
    <item>
      <title>Re: Is the network over designed?</title>
      <link>https://community.cisco.com/t5/network-security/is-the-network-over-designed/m-p/4439482#M1082498</link>
      <description>&lt;P&gt;I suggest a combination of VRFs and a papir of firewalls in HA.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jul 2021 10:18:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/is-the-network-over-designed/m-p/4439482#M1082498</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2021-07-27T10:18:40Z</dc:date>
    </item>
    <item>
      <title>Re: Is the network over designed?</title>
      <link>https://community.cisco.com/t5/network-security/is-the-network-over-designed/m-p/4439721#M1082512</link>
      <description>&lt;P&gt;Also, forgot to mention, whether you use VRFs pr not depends on your design. If you are not doing any routing on the L3 switch then there is no need for VRF so just trunk the VLANs to the firewall.&lt;/P&gt;
&lt;P&gt;I also agree with Leo that with regards to who you choose to do the design and implementation. The cheapest provider on design and implementation often ends up being the most expensive in the long run.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jul 2021 15:49:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/is-the-network-over-designed/m-p/4439721#M1082512</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2021-07-27T15:49:12Z</dc:date>
    </item>
  </channel>
</rss>

