cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
456
Views
5
Helpful
1
Replies

Inserting device into dmz

arrayservices
Level 1
Level 1

I have a question regarding adding a web filter appliance into our dmz segment. Please see the attached diagram.

Here is the scenario: I have a /28 subnet between my internal and external firewalls for L3 connectivity. On our internal firewall, I have a default route for internet traffic pointing to the external firewall (10.10.1.2).

We will be inserting a web filter appliance as indicated on the diagram. The appliance requires an IP address to be assigned to the LAN interface.

What is the best way to accomplish this with minimal impact?

Will my default route on my internal firewall have to change to the IP of the web appliance if I address the web appliance on the 10.10.1.x subnet?

Should I address the web appliance on the 10.10.1.x subnet to begin with, or create a vlan on the 2960 and a L2 interface on one of the firewalls?

Please help!!!!

Brian

1 Reply 1

Andras Dosztal
Level 3
Level 3

I would create a new VLAN/subnet for the web appliance, and redirect the traffic using WCCP or Policy Based Routing (if the appliance doesn't support WCCP).

If you choose WCCP, use version 2. If you use PBR, use IP SLA to monitor the health of the appliance.