<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Best practise: Internet connection direct or through a router? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/best-practise-internet-connection-direct-or-through-a-router/m-p/2810457#M159866</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;So to date I have always had my own router between the firewall and the ISP connection. There have been many legacy reasons for this however they have all disappeared. So now I have two internet connection purely for failover. I know I can plugged these directly into the firewall and run them direct from there. So my question is this....&lt;/P&gt;
&lt;P&gt;Is it better and more secure to have a router between the firewall and the ISP connection or does it not matter/make any difference?&lt;/P&gt;
&lt;P&gt;At present I NAT through the firewall and then NAT between the firewall and the external router depending on the connection running.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Ed&lt;/P&gt;</description>
    <pubDate>Tue, 26 Mar 2019 00:57:59 GMT</pubDate>
    <dc:creator>edw</dc:creator>
    <dc:date>2019-03-26T00:57:59Z</dc:date>
    <item>
      <title>Best practise: Internet connection direct or through a router?</title>
      <link>https://community.cisco.com/t5/network-security/best-practise-internet-connection-direct-or-through-a-router/m-p/2810457#M159866</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;So to date I have always had my own router between the firewall and the ISP connection. There have been many legacy reasons for this however they have all disappeared. So now I have two internet connection purely for failover. I know I can plugged these directly into the firewall and run them direct from there. So my question is this....&lt;/P&gt;
&lt;P&gt;Is it better and more secure to have a router between the firewall and the ISP connection or does it not matter/make any difference?&lt;/P&gt;
&lt;P&gt;At present I NAT through the firewall and then NAT between the firewall and the external router depending on the connection running.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Ed&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 00:57:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/best-practise-internet-connection-direct-or-through-a-router/m-p/2810457#M159866</guid>
      <dc:creator>edw</dc:creator>
      <dc:date>2019-03-26T00:57:59Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/best-practise-internet-connection-direct-or-through-a-router/m-p/2810458#M159869</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;it seems that you need just one device - router or firewall. What functions do you use? Sure, router is not as powerfull as firewall, but for most SMB installations they are enough. If use only NAT without any VPNs and sophisticated filterings, so you can use router alone. If you need advanced firewalling - use firewall alone. Now you have big maintenance overhead by doing NAT two times on different devices.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2016 12:14:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/best-practise-internet-connection-direct-or-through-a-router/m-p/2810458#M159869</guid>
      <dc:creator>dukenuk96</dc:creator>
      <dc:date>2016-02-09T12:14:25Z</dc:date>
    </item>
    <item>
      <title>Well I would always suggest a</title>
      <link>https://community.cisco.com/t5/network-security/best-practise-internet-connection-direct-or-through-a-router/m-p/2810459#M159871</link>
      <description>&lt;P&gt;Well I would always suggest a firewall these days. So we will definitly not be getting rid of the firewall. Yes the NAT is a bit of a maintenance headache thou it doesnt get changed that much.&lt;/P&gt;
&lt;P&gt;I guess the question is does it add to the security or not? Do people just use firewall with the ISP connection plugged stright in? Is this deemed to be secure.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;P.S. Yes we use all the functions of the firewall more or less.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2016 12:18:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/best-practise-internet-connection-direct-or-through-a-router/m-p/2810459#M159871</guid>
      <dc:creator>edw</dc:creator>
      <dc:date>2016-02-09T12:18:36Z</dc:date>
    </item>
    <item>
      <title>So, just use only firewall.</title>
      <link>https://community.cisco.com/t5/network-security/best-practise-internet-connection-direct-or-through-a-router/m-p/2810460#M159873</link>
      <description>&lt;P&gt;So, just use only firewall. If you will need to segment your internal network later, just add L3 switch.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2016 12:25:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/best-practise-internet-connection-direct-or-through-a-router/m-p/2810460#M159873</guid>
      <dc:creator>dukenuk96</dc:creator>
      <dc:date>2016-02-09T12:25:36Z</dc:date>
    </item>
    <item>
      <title>Yes we have redundant</title>
      <link>https://community.cisco.com/t5/network-security/best-practise-internet-connection-direct-or-through-a-router/m-p/2810461#M159875</link>
      <description>&lt;P&gt;Yes we have redundant Catalyst routers internally and have multiple VLAN's.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2016 12:28:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/best-practise-internet-connection-direct-or-through-a-router/m-p/2810461#M159875</guid>
      <dc:creator>edw</dc:creator>
      <dc:date>2016-02-09T12:28:19Z</dc:date>
    </item>
    <item>
      <title>Even better if you already</title>
      <link>https://community.cisco.com/t5/network-security/best-practise-internet-connection-direct-or-through-a-router/m-p/2810462#M159876</link>
      <description>&lt;P&gt;Even better if you already have this.. but how do you connect them to firewall?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2016 12:35:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/best-practise-internet-connection-direct-or-through-a-router/m-p/2810462#M159876</guid>
      <dc:creator>dukenuk96</dc:creator>
      <dc:date>2016-02-09T12:35:10Z</dc:date>
    </item>
    <item>
      <title>The core routers is connected</title>
      <link>https://community.cisco.com/t5/network-security/best-practise-internet-connection-direct-or-through-a-router/m-p/2810463#M159879</link>
      <description>&lt;P&gt;The core routers is connected via a ethernet cable to one port. The router forwards all network traffic going outside or to DMZ to the firewall's IP. If that's what you mean.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2016 12:42:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/best-practise-internet-connection-direct-or-through-a-router/m-p/2810463#M159879</guid>
      <dc:creator>edw</dc:creator>
      <dc:date>2016-02-09T12:42:48Z</dc:date>
    </item>
    <item>
      <title>Typically no it doesn't add</title>
      <link>https://community.cisco.com/t5/network-security/best-practise-internet-connection-direct-or-through-a-router/m-p/2810464#M159880</link>
      <description>&lt;P&gt;Typically no it doesn't add to security although some people do basic filtering of IPs you shouldn't see before the traffic gets to the firewall.&lt;/P&gt;
&lt;P&gt;Routers were used primarily in the past because of different media types for the internet connection and because they are more flexible in terms of things like PBR, QOS etc.&lt;/P&gt;
&lt;P&gt;The ASAs now support PBR (although it does seem to have some bugs) so you don't really gain much by having routers to be honest if you don't need them.&lt;/P&gt;
&lt;P&gt;Your firewall is the security so it really doesn't matter too much if the ISP connection is direct or via&amp;nbsp;a router.&lt;/P&gt;
&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2016 12:45:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/best-practise-internet-connection-direct-or-through-a-router/m-p/2810464#M159880</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2016-02-09T12:45:45Z</dc:date>
    </item>
    <item>
      <title>I mean quite another - you</title>
      <link>https://community.cisco.com/t5/network-security/best-practise-internet-connection-direct-or-through-a-router/m-p/2810465#M159883</link>
      <description>&lt;P&gt;I mean quite another - you have two Catalysts as the core of your network and one firewall. How phyisical connection from Catalyst(s) to firewall is implemented? I mean is there some kind of failover link?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2016 12:48:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/best-practise-internet-connection-direct-or-through-a-router/m-p/2810465#M159883</guid>
      <dc:creator>dukenuk96</dc:creator>
      <dc:date>2016-02-09T12:48:57Z</dc:date>
    </item>
    <item>
      <title>No at present there is no</title>
      <link>https://community.cisco.com/t5/network-security/best-practise-internet-connection-direct-or-through-a-router/m-p/2810466#M159885</link>
      <description>&lt;P&gt;No at present there is no failover but we are looking at that right at this moment as i have been given another firewall by another charity. So will be using it in a failover.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2016 15:00:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/best-practise-internet-connection-direct-or-through-a-router/m-p/2810466#M159885</guid>
      <dc:creator>edw</dc:creator>
      <dc:date>2016-02-09T15:00:44Z</dc:date>
    </item>
    <item>
      <title>Okay, so I meant that now you</title>
      <link>https://community.cisco.com/t5/network-security/best-practise-internet-connection-direct-or-through-a-router/m-p/2810467#M159886</link>
      <description>&lt;P&gt;Okay, so I meant that now you have one pint of failure and I strongly recommend moving to failover design.&lt;/P&gt;
&lt;P&gt;Good luck!&lt;/P&gt;</description>
      <pubDate>Wed, 10 Feb 2016 05:40:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/best-practise-internet-connection-direct-or-through-a-router/m-p/2810467#M159886</guid>
      <dc:creator>dukenuk96</dc:creator>
      <dc:date>2016-02-10T05:40:36Z</dc:date>
    </item>
  </channel>
</rss>

