cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
451
Views
0
Helpful
1
Replies

VPN Implementation

llou
Level 1
Level 1

Hi all,

I have a rather simply question.

I have recently purchased a Cisco Concentrator 3000 for my company and would like to deploy either on the DMZ or the external (outside the fw) using L2TP/IPSec.

I want to know all of the pro and con regarding these 2 setups. I would love to hear your advice. Thanks.

Larry

1 Reply 1

gary.cf.wong
Level 1
Level 1

What I can think of:

Placing at external, your VPN box will be exposed to any attack. At DMZ, fw is the first line of security before traffic going to the VPN box itself. Another approach would be building DMZ1 and DMZ2, having the public and private legs of VPN plugged to these 2 DMZs, you can then enforce firewalling for IPSec clients accessing the internal.