cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
239
Views
0
Helpful
1
Replies

Firewall behind a single 3662 router

guille
Level 1
Level 1

I have a 3662 router with have two ISP connections with BGP4, one port for my intranet (2 VLANS) connected to a catalyst switch, another port for DMZ, and T1 for VOIP. As you can see this is my main (gateway) router. I am running the Firewall IOS on it

I want to install a Firewall/VPN in my network and I want to know what will be the best design for it. All the designs that I have seen have one router for the Internet and another for the Intranet. This is not my case. Everything is on the same router.

Who can I block the router to "router" he trafic from the Intranet to the Internet and instead send it to the firewall? And the firewall will send it back to the same router...

Does some one help me designing this.

Thanks,

Guillermo

1 Reply 1

hadbou
Level 5
Level 5

My personnel opinion on your current design is taht you are over tasking your router by having everything on the same router.

You can still have the following

internet --- router --- Firewall --- Intranet.