<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to implement Dual firewall. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-to-implement-dual-firewall/m-p/2578220#M199208</link>
    <description>&lt;P&gt;Hello;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to implement dual firewalls in my network, one facing to internet and another one facing to LAN, currently I have a Firewall B facing to internet and LAN and have a IPsec VPN for site to site.&amp;nbsp; If I need to place a new Firewall A in front of Firewall B and facing to internet, where should I teminate my site to site VPN?&amp;nbsp; And how to direct the traffic from interent to Firewall A, then Firewall B, using double NATTING? or all any any from Outside interface of Firewall A to the Outside interface of Firewall B?&amp;nbsp; I am using ASA 5512X.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;LAN ---&amp;gt; Firewall B ---------&amp;gt; Firewall A --------&amp;gt; Internet&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DMZ&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How to direct the traffic from internet back to LAN?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 05:19:28 GMT</pubDate>
    <dc:creator>kkwaskcisco</dc:creator>
    <dc:date>2019-03-12T05:19:28Z</dc:date>
    <item>
      <title>How to implement Dual firewall.</title>
      <link>https://community.cisco.com/t5/network-security/how-to-implement-dual-firewall/m-p/2578220#M199208</link>
      <description>&lt;P&gt;Hello;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to implement dual firewalls in my network, one facing to internet and another one facing to LAN, currently I have a Firewall B facing to internet and LAN and have a IPsec VPN for site to site.&amp;nbsp; If I need to place a new Firewall A in front of Firewall B and facing to internet, where should I teminate my site to site VPN?&amp;nbsp; And how to direct the traffic from interent to Firewall A, then Firewall B, using double NATTING? or all any any from Outside interface of Firewall A to the Outside interface of Firewall B?&amp;nbsp; I am using ASA 5512X.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;LAN ---&amp;gt; Firewall B ---------&amp;gt; Firewall A --------&amp;gt; Internet&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DMZ&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How to direct the traffic from internet back to LAN?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:19:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-implement-dual-firewall/m-p/2578220#M199208</guid>
      <dc:creator>kkwaskcisco</dc:creator>
      <dc:date>2019-03-12T05:19:28Z</dc:date>
    </item>
    <item>
      <title>Hi, What is the reason of</title>
      <link>https://community.cisco.com/t5/network-security/how-to-implement-dual-firewall/m-p/2578221#M199209</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is the reason of inserting another firewall in front of the currently used firewall?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With regards to the VPN I would rather use the VPN on the firewall on the edge of the network or have a separate VPN gateway device on the edge of the network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am not sure that I understand the problem with forwarding the traffic? You should simply have the proper routes configured on the firewalls and other connected devices to forward the traffic correctly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also don't really understand what you mean by the double NAT in this case?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think we need some clarifications on why you are changing the setup like this and what you want to achieve.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jan 2015 12:04:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-implement-dual-firewall/m-p/2578221#M199209</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2015-01-12T12:04:52Z</dc:date>
    </item>
    <item>
      <title>Hi Jouni Thanks for your</title>
      <link>https://community.cisco.com/t5/network-security/how-to-implement-dual-firewall/m-p/2578222#M199213</link>
      <description>&lt;P&gt;Hi Jouni&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your response.&amp;nbsp; The reason of placing a 2nd firewall facing to internet is for security reason, try to enhance the security in network.&lt;/P&gt;&lt;P&gt;I was thinking to put the route also but not sure if this is the correct path to do.&amp;nbsp; I was thinking, the connection like this way.&lt;/P&gt;&lt;P&gt;1. connect the WAN interface of Firewall B to LAN interface of Firewall A with a network cable. (I think this is correct connection)&lt;/P&gt;&lt;P&gt;2. Assign a LAN ip for Firewall B WAN interface, like 192.168.0.1&lt;/P&gt;&lt;P&gt;3. Assign a LAN ip for LAN interface of Firewall A, like 192.168.0.254&lt;/P&gt;&lt;P&gt;4. Assign the public ISP IP for WAN interface on Firewall A for internet connection.&lt;/P&gt;&lt;P&gt;5. On Firewall B, using a static route to route all inbound traffic from any any through 192.168.0.254 because 192.168.0.254 will be the gateway.&lt;/P&gt;&lt;P&gt;route outside 0 0 192.168.0.254&lt;/P&gt;&lt;P&gt;6. On Firewall A, routing all traffic to internet through ISP gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But, what will be the command looks like for inbound traffic from Firewall A to Firewall B, then to ensure that it can go to the LAN side on Firewall B?&lt;/P&gt;</description>
      <pubDate>Sat, 17 Jan 2015 02:28:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-implement-dual-firewall/m-p/2578222#M199213</guid>
      <dc:creator>kkwaskcisco</dc:creator>
      <dc:date>2015-01-17T02:28:28Z</dc:date>
    </item>
  </channel>
</rss>

