02-10-2011 10:34 AM - edited 03-11-2019 12:48 PM
Hi friends,
I need some clarification on the below setup.
Is it possible to use Dept firewall as a routed firewall or Multiple content based firewall.
because I need to segregate the dept from the above core switch.
Pls send your suggestions.
Thanks in advance.
02-10-2011 10:38 AM
Hi,
I don't see your setup included.
If you have an ASA (other than 5505) you can either use it routed/transparent or multiple/single mode.
Federico.
02-10-2011 10:41 AM
02-10-2011 06:33 PM
I would use those ASAs in single mode and in routed mode.
Is there any special reason why to want them in multiple context mode or transparent?
If you set the ASA to multiple context you lose functionality as VPN for example.
In transparent mode there's no VPN as well as well as other limitations.
In other words, if there's no special reason as to why to change the operating mode of the ASA, I'll suggest to keep them in single/routed mode.
Federico.
02-10-2011 11:55 PM
Hi Federico,
Thanks for your reply,
I don't use VPN, Dynamic routing and multicast in the Dept firewall.
I have some questions in below:
If i use Multiple content mode in the firewall, it will affect performance of the CPU or not.
because i have access rule around 60 lines.
If i use multiple content, then i can totally segregated the two networks connected to the Dept firewall.
One is Internet link to Dept and another one is Dept to Dept segregation.
Pls send ur suggestion.
thanks,
Saravanan.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide