03-19-2014 07:45 PM - edited 03-07-2019 06:47 PM
Hi,
Which one is a better design?
To terminate VPN connection at Router level or Firewall level.
For a case of: SW----FW---Router?
Based on many review it seems terminating VPN at router level is much more troublesome to configure as compared to terminate at router level.
Appreciate any feedback. Thanks.
Solved! Go to Solution.
03-21-2014 07:53 AM
For SSL remote access VPN I would suggest terminating it on the firewall. If your outside connection is some connection type that the firewall does not support then it makes sense to have the router on the outside.
HTH
Rick
03-20-2014 06:59 AM
It is not clear to me in your post where the inside network is and where the outside/Internet is. I am guessing that the switch is the inside and the outside is connected at router. Is that correct? I wonder about changing the topology so that the firewall is the connection to outside and the router is inside of the firewall.
It is also not clear whether you are talking about remote access VPN or site to site VPN. For remote access VPN I would advise terminating it on the firewall. For site to site VPN I would advise terminating it on the router.
HTH
Rick
03-20-2014 08:32 PM
03-21-2014 07:53 AM
For SSL remote access VPN I would suggest terminating it on the firewall. If your outside connection is some connection type that the firewall does not support then it makes sense to have the router on the outside.
HTH
Rick
04-01-2014 09:18 AM
Hi guys,
Ty for the replies.
Currenty the router which internet facing only has one WAN IP address but the SSL remote access VPN is on the firewall which behind the router.
How can i make remote access user connect to the firewall via public IP since the only way to connect is to the router first.
04-01-2014 01:21 PM
That is a challenge. Perhaps you might do port forwarding on the router so that SSL was translated and forwarded to the ASA address.
HTH
Rick
03-21-2014 07:32 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide