cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
782
Views
0
Helpful
6
Replies

MSE Desgin

For network design ,is there any best practice or recommendation for installing MSE  , is there any problem for installing MSE & WCS/Prime inside datacenter behind firewall
OR it is better to install WCS/Prime & MSE beside WLCs without firewall 

Thanks

6 Replies 6

Scott Fella
Hall of Fame
Hall of Fame

The only device that should be behind the FW is an anchor WLC. Most of all my designs have the WLC's, PI, and MSE in the inside and maybe in different subnets, but only a guest anchor WLC would be behind a FW in the DMZ.

-Scott

-Scott
*** Please rate helpful posts ***

Thanks Scott and moh_setan1988 for your help

I just wanted to know if there was any best practice for this point or not ,because i searched a lot in cisco documents and did not find any thing taking about this

Also i was thinking would be it be safe to put WCS/Prime without any firewall protecting them from network threats 

Did any one face problem with that before

 

Thanks

Ahmed

There is no reason to really place them behind a firewall. Prime typically is on a VM so that's usually placed in the server vlan. MSE also can be a VM and placed in the same server vlan. Appliance have been treated like servers also, so look at where your servers are currently placed. If it's behind a firewall due to you companies policies, then both should be placed behind the firewall for consistency. If you look at many of the design documents, these devices are in the internal network and not in the DMZ.  Most companies don't want to poke holes in the firewall for these devices to sit in because they believe now your opening up the firewall more to threats. 

-Scott

-Scott
*** Please rate helpful posts ***

Thanks scott that was convincing analysis

 

Thanks

Ahmed

No problem

-Scott

-Scott
*** Please rate helpful posts ***

moh_setan1988
Level 1
Level 1

Hi Ahmed,

 

There is no issue with adding the devices behind the firewall, but you need to make sure that the ports that are used between the WLC <-> MSE and MSE <-> WCS are all opened.

 

You can refer to the link below which is showing the needed ports for the communication:

http://www.cisco.com/c/en/us/support/docs/wireless/5500-series-wireless-controllers/113344-cuwn-ppm.html

 

Kind Regards

Mohammad Setan

Review Cisco Networking for a $25 gift card