<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic firewall - vpn question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firewall-vpn-question/m-p/1832546#M490832</link>
    <description>&lt;P&gt;hi! I've a firewall with 4 nic card, 2 of those nics are connected to the public and private&amp;nbsp; dmz respectively. The remaining 2 nics are connected to the public internet and internal lan each.&lt;/P&gt;&lt;P&gt;eg.&lt;/P&gt;&lt;P&gt;Nic1 - Public&amp;nbsp; DMZ &lt;/P&gt;&lt;P&gt;Nic2 - Private&amp;nbsp;&amp;nbsp; DMZ&lt;/P&gt;&lt;P&gt;Nic3 - Internet (telco router)&lt;/P&gt;&lt;P&gt;Nic4 - Internal LAN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If' I would to setup a vpn concentrator (for small sites to establish tunnel to it) which itself is a firewall, what's the advantage of having these vpn concentrator on the public/private dmz zone over direct connection to the internal lan? and vise versa? Thanks.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 22:03:33 GMT</pubDate>
    <dc:creator>dave dave</dc:creator>
    <dc:date>2019-03-11T22:03:33Z</dc:date>
    <item>
      <title>firewall - vpn question</title>
      <link>https://community.cisco.com/t5/network-security/firewall-vpn-question/m-p/1832546#M490832</link>
      <description>&lt;P&gt;hi! I've a firewall with 4 nic card, 2 of those nics are connected to the public and private&amp;nbsp; dmz respectively. The remaining 2 nics are connected to the public internet and internal lan each.&lt;/P&gt;&lt;P&gt;eg.&lt;/P&gt;&lt;P&gt;Nic1 - Public&amp;nbsp; DMZ &lt;/P&gt;&lt;P&gt;Nic2 - Private&amp;nbsp;&amp;nbsp; DMZ&lt;/P&gt;&lt;P&gt;Nic3 - Internet (telco router)&lt;/P&gt;&lt;P&gt;Nic4 - Internal LAN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If' I would to setup a vpn concentrator (for small sites to establish tunnel to it) which itself is a firewall, what's the advantage of having these vpn concentrator on the public/private dmz zone over direct connection to the internal lan? and vise versa? Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:03:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-vpn-question/m-p/1832546#M490832</guid>
      <dc:creator>dave dave</dc:creator>
      <dc:date>2019-03-11T22:03:33Z</dc:date>
    </item>
    <item>
      <title>firewall - vpn question</title>
      <link>https://community.cisco.com/t5/network-security/firewall-vpn-question/m-p/1832547#M490834</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Cisco VPN concentrator is not a pure firewall- below is&amp;nbsp; the extract from Cisco VPN conc Q&amp;amp;A with ref to the same:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Q. Does the Cisco VPN 3000 Concentrator Series have an integrated firewall? If so, what features are supported?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;A. &lt;/STRONG&gt;While the series has integrated stateless port / filtering capabilities and NAT, Cisco suggests you use a device like the Cisco Secure PIX Firewall for the corporate firewall&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With reference to placement of the VPN concentrator, it can be placed in front of, behind, parallel to, or in the demilitarized zone (DMZ) of firewall based on your design requirement. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The DMZ implementation- gives you more control on what the remote users can access (good in terms of firm security). In parallel to ASA - basically opens your LAN for remote partners.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hth&lt;/P&gt;&lt;P&gt;MS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Dec 2011 16:24:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-vpn-question/m-p/1832547#M490834</guid>
      <dc:creator>mvsheik123</dc:creator>
      <dc:date>2011-12-19T16:24:09Z</dc:date>
    </item>
  </channel>
</rss>

