<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic security scenario deployment in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/security-scenario-deployment/m-p/1771749#M496747</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kunal,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Answer 1.&amp;nbsp; You can do that if you want, you can assign the servers directly a public ip address, there should not be an issue with.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Answer2.&amp;nbsp; My personal opinion would be, scenario 1, just because of the security provided by it, the outside world doesn't really know the real ip of the server, moreover due to teh scalibility option, i can save public ip's by doing it. If you do port forwarding, you can even use same ip for multiple internal servers running different application, makes more sense.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Answer 3. Scenario 1 until it is a requirement to implement scenario 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 29 Sep 2011 18:10:01 GMT</pubDate>
    <dc:creator>varrao</dc:creator>
    <dc:date>2011-09-29T18:10:01Z</dc:date>
    <item>
      <title>security scenario deployment</title>
      <link>https://community.cisco.com/t5/network-security/security-scenario-deployment/m-p/1771748#M496746</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a cisco ASA firewall.&lt;/P&gt;&lt;P&gt;Outside - Connected to Internet.&lt;/P&gt;&lt;P&gt;DMZ- Connected to servers which open up connections to the Inside zone.&lt;/P&gt;&lt;P&gt;Inside - secure applications.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scenario 1&lt;/P&gt;&lt;P&gt;when request from the Internet hits the firewall public OUTSIDE ip. I nat it to a private ip in DMZ zone has the servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scenario 2&lt;/P&gt;&lt;P&gt;I can have the request from the Internet hit the DMZ zonedirectly instead of the outside zone provided the DMZ zone servers are in the public range ...is this correct? question1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;question2) So the question is when I would use scenario 1 and when I would use scenario 2.&lt;/P&gt;&lt;P&gt;question3) Which is considered a best practice?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-----------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Kunal&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:32:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-scenario-deployment/m-p/1771748#M496746</guid>
      <dc:creator>kunal-united</dc:creator>
      <dc:date>2019-03-11T21:32:13Z</dc:date>
    </item>
    <item>
      <title>security scenario deployment</title>
      <link>https://community.cisco.com/t5/network-security/security-scenario-deployment/m-p/1771749#M496747</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kunal,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Answer 1.&amp;nbsp; You can do that if you want, you can assign the servers directly a public ip address, there should not be an issue with.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Answer2.&amp;nbsp; My personal opinion would be, scenario 1, just because of the security provided by it, the outside world doesn't really know the real ip of the server, moreover due to teh scalibility option, i can save public ip's by doing it. If you do port forwarding, you can even use same ip for multiple internal servers running different application, makes more sense.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Answer 3. Scenario 1 until it is a requirement to implement scenario 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Sep 2011 18:10:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-scenario-deployment/m-p/1771749#M496747</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-09-29T18:10:01Z</dc:date>
    </item>
  </channel>
</rss>

