<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACL in layer 3 switch compare to ASA firewall in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/acl-in-layer-3-switch-compare-to-asa-firewall/m-p/1950671#M401696</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I personally feel bringing a firewall in this scenario is the best choice to secure the network. Even though your switch can do the ACL but ACL in firewall will be a good solution. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Switch will do a better switching &amp;amp; firewall will do a better security for your network. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Having ACL in switch will gives a more load to the switch and its stateless.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use ACL's is switch for Qos/Line vty restriction/local host restriction. But intresting traffic towards WAN/Internet should be done with the Firewall as a best practice.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please do rate if the given information helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;by&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Karthik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 24 Jul 2012 10:38:59 GMT</pubDate>
    <dc:creator>nkarthikeyan</dc:creator>
    <dc:date>2012-07-24T10:38:59Z</dc:date>
    <item>
      <title>ACL in layer 3 switch compare to ASA firewall</title>
      <link>https://community.cisco.com/t5/network-security/acl-in-layer-3-switch-compare-to-asa-firewall/m-p/1950669#M401694</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have got a task of limiting 2-3 VLANs communication to allow only some services like File sharing / Printing / Email / AD connections.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure if a layer 3 switch with ACL is already good enough for limiting the listed services?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or I need a real firewall between the networks?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The purpose of limited to the list services is for security reason like hacked / virus pc in a VLAN spreading to all other VLANs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please advise.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Roy&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:33:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-in-layer-3-switch-compare-to-asa-firewall/m-p/1950669#M401694</guid>
      <dc:creator>Roy Lee</dc:creator>
      <dc:date>2019-03-11T23:33:59Z</dc:date>
    </item>
    <item>
      <title>ACL in layer 3 switch compare to ASA firewall</title>
      <link>https://community.cisco.com/t5/network-security/acl-in-layer-3-switch-compare-to-asa-firewall/m-p/1950670#M401695</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My recommendation is to have a firewall instead of using switch. Reason being switch is designed to switch/route packet as fast as possible and having access-list is just denying or allowing stateless connection. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With firewall, it is inspecting the traffic statefully, and have other features by default that prevent various attacks, ie: maintaining the TCP session and incomplete session will be dropped by the firewall, various application layer inspections, etc.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Jul 2012 09:20:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-in-layer-3-switch-compare-to-asa-firewall/m-p/1950670#M401695</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-07-24T09:20:05Z</dc:date>
    </item>
    <item>
      <title>ACL in layer 3 switch compare to ASA firewall</title>
      <link>https://community.cisco.com/t5/network-security/acl-in-layer-3-switch-compare-to-asa-firewall/m-p/1950671#M401696</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I personally feel bringing a firewall in this scenario is the best choice to secure the network. Even though your switch can do the ACL but ACL in firewall will be a good solution. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Switch will do a better switching &amp;amp; firewall will do a better security for your network. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Having ACL in switch will gives a more load to the switch and its stateless.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use ACL's is switch for Qos/Line vty restriction/local host restriction. But intresting traffic towards WAN/Internet should be done with the Firewall as a best practice.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please do rate if the given information helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;by&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Karthik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Jul 2012 10:38:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-in-layer-3-switch-compare-to-asa-firewall/m-p/1950671#M401696</guid>
      <dc:creator>nkarthikeyan</dc:creator>
      <dc:date>2012-07-24T10:38:59Z</dc:date>
    </item>
    <item>
      <title>ACL in layer 3 switch compare to ASA firewall</title>
      <link>https://community.cisco.com/t5/network-security/acl-in-layer-3-switch-compare-to-asa-firewall/m-p/1950672#M401699</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bro&lt;/P&gt;&lt;P&gt;If the rules you want to apply are just few lines &amp;lt;10, go ahead and use the switch. Of course, it's good to have a dedicated FW for this, but if it's just for few lines, don't waste your company's money &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Jul 2012 02:49:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-in-layer-3-switch-compare-to-asa-firewall/m-p/1950672#M401699</guid>
      <dc:creator>Ramraj Sivagnanam Sivajanam</dc:creator>
      <dc:date>2012-07-27T02:49:44Z</dc:date>
    </item>
    <item>
      <title>Re:ACL in layer 3 switch compare to ASA firewall</title>
      <link>https://community.cisco.com/t5/network-security/acl-in-layer-3-switch-compare-to-asa-firewall/m-p/1950673#M401703</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello roy,&lt;/P&gt;&lt;P&gt;You have to understand that the asa blocks traffic by default and you have to allow what is required.&lt;/P&gt;&lt;P&gt;Switches and routers by default allow all and you configure what is to be blocked. So if you have a lot of traffic passing through that por the cpu might get hit.&lt;/P&gt;&lt;P&gt;Asa is the recommended device for that job.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support Android App&lt;/P&gt;&lt;P&gt;Pls rate useful posts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Jul 2012 16:48:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-in-layer-3-switch-compare-to-asa-firewall/m-p/1950673#M401703</guid>
      <dc:creator>Durga Prasad M.S</dc:creator>
      <dc:date>2012-07-27T16:48:03Z</dc:date>
    </item>
  </channel>
</rss>

