<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firewall in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firewall/m-p/1421231#M731581</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;Hello I have&amp;nbsp; 3 sites and Core
sites , i want to ask which better place in each site Firewall blade on
6509 switch or place central Firewall on the core sites&lt;/P&gt;&lt;P&gt;and applay the police on all site on this firewall .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i want choose the best practical design to do that , any one better and why ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the design 1&amp;nbsp; and design 2 in the attachments&lt;/P&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For your query if you deploy a firewall at each sites it will be better because only controlled traffic will be coming from remote sites to central site and you can manage those firewall from central site also.In these type of design you are doing two level security layer one at local site firewall and other at central site.so traffic will be filtered at two area before entering into central site.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you deploy only at central site that is also a recommended design to control traffic to enter into central site but you cannot controll traffic which will be routed between site to site as there no firewall at remote sites.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both the design only be differ in cost areas as one firewall blade ate central site will low cost and at all location blade will be bit higher.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope to help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Ganesh.H&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 24 Jan 2010 09:24:25 GMT</pubDate>
    <dc:creator>Ganesh Hariharan</dc:creator>
    <dc:date>2010-01-24T09:24:25Z</dc:date>
    <item>
      <title>Firewall</title>
      <link>https://community.cisco.com/t5/network-security/firewall/m-p/1421229#M731567</link>
      <description>&lt;P&gt;Hello I have&amp;nbsp; 3 sites and Core sites , i want to ask which better place in each site Firewall blade on 6509 switch or place central Firewall on the core sites&lt;/P&gt;&lt;P&gt;and applay the police on all site on this firewall .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i want choose the best practical design to do that , any one better and why ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the design 1&amp;nbsp; and design 2 in the attachments&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:00:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall/m-p/1421229#M731567</guid>
      <dc:creator>engmohamad1980</dc:creator>
      <dc:date>2019-03-11T17:00:35Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall</title>
      <link>https://community.cisco.com/t5/network-security/firewall/m-p/1421230#M731574</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To design a network, you will first need to analyze how much&lt;STRONG&gt; traffic&lt;/STRONG&gt; will be flowing throughout the LAN, then figure out which sites needs to be given restriced access or how much security is needed, and of course how much money you are willing to put in this whole operation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Design 1 looks costly, as you are planning to install firewall at each site, (assuming each core site needs a high end device like 5540/5580). But again this approach is very secure, as you can restrict access for devices behind each core more granularly, with help of INDIVIDUAL firewall ACL rules, MPF, etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Design 2 at the other hand may be cheaper. Here you may not have as granular control over security of each core network. You can definitely achieve more control over traffic going out to internet from all core n/w, as they all will need to pass through the single firewall (gateway) in picture.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;So, here I am including datasheet of all Cisco ASAs which you may go through to find out the best one that suits the needs of your network:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/product_data_sheet0900aecd802930c5.html"&gt;http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/product_data_sheet0900aecd802930c5.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vijaya&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 24 Jan 2010 04:55:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall/m-p/1421230#M731574</guid>
      <dc:creator>vilaxmi</dc:creator>
      <dc:date>2010-01-24T04:55:36Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall</title>
      <link>https://community.cisco.com/t5/network-security/firewall/m-p/1421231#M731581</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;Hello I have&amp;nbsp; 3 sites and Core
sites , i want to ask which better place in each site Firewall blade on
6509 switch or place central Firewall on the core sites&lt;/P&gt;&lt;P&gt;and applay the police on all site on this firewall .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i want choose the best practical design to do that , any one better and why ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the design 1&amp;nbsp; and design 2 in the attachments&lt;/P&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For your query if you deploy a firewall at each sites it will be better because only controlled traffic will be coming from remote sites to central site and you can manage those firewall from central site also.In these type of design you are doing two level security layer one at local site firewall and other at central site.so traffic will be filtered at two area before entering into central site.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you deploy only at central site that is also a recommended design to control traffic to enter into central site but you cannot controll traffic which will be routed between site to site as there no firewall at remote sites.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both the design only be differ in cost areas as one firewall blade ate central site will low cost and at all location blade will be bit higher.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope to help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Ganesh.H&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 24 Jan 2010 09:24:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall/m-p/1421231#M731581</guid>
      <dc:creator>Ganesh Hariharan</dc:creator>
      <dc:date>2010-01-24T09:24:25Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall</title>
      <link>https://community.cisco.com/t5/network-security/firewall/m-p/1421232#M731593</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN class="long_text" id="result_box"&gt;&lt;SPAN title="موضوع التكلفة يوجد ميزانية ، المشروع لجامعة دولية عدد المستخدمين فيها ٦٠٠٠ ، تتألف من عدة مواقع وكل موقع تقريبا يحوي ١٥٠٠ مستخدم ،"&gt;Cost is the subject of budget, the project to an international university, the number of those employed in 6000, consisting of several sites, each site contains approximately 1500 consumers,&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="انا حالياً مقتنع بالتصميم رقم ١ ، ولكن هل يوجد سؤالين ."&gt;I am currently convinced design No. 1, but are there two questions.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="‎١- هل يوجد مشروع مشابة عالمياً ليتم اقناع المدير فيه ."&gt;1 - Is there a similar project is to convince the world of Director.&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="‎٢- ما هو الافضل استخدام بلاد firewall"&gt;2 - What is the best to use the Blade firewall on switch 6509 or use ASA Firewall standalone .&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks all&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 24 Jan 2010 17:29:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall/m-p/1421232#M731593</guid>
      <dc:creator>engmohamad1980</dc:creator>
      <dc:date>2010-01-24T17:29:24Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall</title>
      <link>https://community.cisco.com/t5/network-security/firewall/m-p/1421233#M731601</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;&lt;SPAN class="long_text" id="result_box"&gt;&lt;SPAN title="موضوع التكلفة يوجد ميزانية ، المشروع لجامعة دولية عدد المستخدمين فيها ٦٠٠٠ ، تتألف من عدة مواقع وكل موقع تقريبا يحوي ١٥٠٠ مستخدم ،"&gt;Cost
is the subject of budget, the project to an international university,
the number of those employed in 6000, consisting of several sites, each
site contains approximately 1500 consumers,&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="انا حالياً مقتنع بالتصميم رقم ١ ، ولكن هل يوجد سؤالين ."&gt;I am currently convinced design No. 1, but are there two questions.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="‎١- هل يوجد مشروع مشابة عالمياً ليتم اقناع المدير فيه ."&gt;1 - Is there a similar project is to convince the world of Director.&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="‎٢- ما هو الافضل استخدام بلاد firewall"&gt;2 - What is the best to use the Blade firewall on switch 6509 or use ASA Firewall standalone .&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks all&lt;/P&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check out the below link for feature set between ASA and FWSM hope it will help out your query !!&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://docwiki.cisco.com/wiki/Feature_Differences"&gt;http://docwiki.cisco.com/wiki/Feature_Differences&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If helpful do rate the valaubale post.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Ganesh.H&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Jan 2010 09:46:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall/m-p/1421233#M731601</guid>
      <dc:creator>Ganesh Hariharan</dc:creator>
      <dc:date>2010-01-25T09:46:41Z</dc:date>
    </item>
  </channel>
</rss>

