<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA selection in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-selection/m-p/2200879#M361801</link>
    <description>&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;SPAN&gt;My customer is designing an architecture with two networks - internal and external. In between these two networks will be a DMZ where a layer 7 gateway device will reside. This layer 7 device (which could from Layer 7 - SecureSpan SOA Gateway - see &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.layer7tech.com/products/soa-gateway" target="_blank"&gt;http://www.layer7tech.com/products/soa-gateway&lt;/A&gt;&lt;SPAN&gt;) will act as a mediation and policy enforcement point between the internal and external networks using XML. This device as required as there is a requirement for different applications to send and receive different data. The XML is used to accomplish this.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My customer would want to use ASA firewalls to bookend the DMZ. Their question, "Do the ASA 55XX firewalls communication via XML and are they a layer 7 device?". &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, are two firewalls required? Which ASA would work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;David Stehle&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 01:02:24 GMT</pubDate>
    <dc:creator>dstehle</dc:creator>
    <dc:date>2019-03-12T01:02:24Z</dc:date>
    <item>
      <title>ASA selection</title>
      <link>https://community.cisco.com/t5/network-security/asa-selection/m-p/2200879#M361801</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;SPAN&gt;My customer is designing an architecture with two networks - internal and external. In between these two networks will be a DMZ where a layer 7 gateway device will reside. This layer 7 device (which could from Layer 7 - SecureSpan SOA Gateway - see &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.layer7tech.com/products/soa-gateway" target="_blank"&gt;http://www.layer7tech.com/products/soa-gateway&lt;/A&gt;&lt;SPAN&gt;) will act as a mediation and policy enforcement point between the internal and external networks using XML. This device as required as there is a requirement for different applications to send and receive different data. The XML is used to accomplish this.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My customer would want to use ASA firewalls to bookend the DMZ. Their question, "Do the ASA 55XX firewalls communication via XML and are they a layer 7 device?". &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, are two firewalls required? Which ASA would work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;David Stehle&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:02:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-selection/m-p/2200879#M361801</guid>
      <dc:creator>dstehle</dc:creator>
      <dc:date>2019-03-12T01:02:24Z</dc:date>
    </item>
    <item>
      <title>ASA selection</title>
      <link>https://community.cisco.com/t5/network-security/asa-selection/m-p/2200880#M361802</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;While ASA can provide inspection of certain protocols, it does not provide XML inspection. If you configure your traffic policies correctly, you can allow XML communication from outside to DMZ and from DMZ to inside, depending on your requirements. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For your deployemnt, one firewall would be sufficient, but you could use two identical appliances to provide high availability.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Choosing the right firewall depends on other parameters:&lt;/P&gt;&lt;P&gt;- what is the bandwidth required across this firewall&lt;/P&gt;&lt;P&gt;- do you wish to terminate VPNs on this firewall ? if so, how many ?&lt;/P&gt;&lt;P&gt;- how many and which physical interfaces do you require&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can find the current datasheets at the links below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Small and SoHo appliances: &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/data_sheet_c78-701253.html"&gt;http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/data_sheet_c78-701253.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Internet Edge appliances:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/data_sheet_c78-701808.html"&gt;http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/data_sheet_c78-701808.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Mar 2013 18:30:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-selection/m-p/2200880#M361802</guid>
      <dc:creator>stojanr</dc:creator>
      <dc:date>2013-03-12T18:30:06Z</dc:date>
    </item>
  </channel>
</rss>

