Hi,
I plan to migrate current Juniper SSG-320M to ASA5516.
We have 3 subnet public IP ( server NIC configure with Public IP).
The current firewall only 2 zone, Trust and Untrust adn 2 cable one to uplink and one to Internal.
I'm confious why current juniper no IP configure at port ( only 1 subnet public IP configure at vlan1).
If I want to whitelist between public ip subnet internal ,the current rules i need to whitelist at both zone untrust to trust & trust to untrust.
Routing did by provider. Is this transparent firewall ?
My config at ASA later no need to add IP subnet at port ?
or require to add 3 subnet as sub-interfcae ? since only 1 cable to Internal/trust.
or need to make ASA as transparent ?
Attached is the screenshot at Juniper netscreen.
Kindly helpp