Protecting the WAN interface

Unanswered Question
Apr 6th, 2008


I have a Firewall,whose Outside interface is connected to a ISP with a Public IP address,now I want to protect this Outside interface.How can I do this?Basically it is like a Hardening the Firewall or a Router which is directly exposed to global network.

Please help me.

Thanks and Regards,


I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
JORGE RODRIGUEZ Sun, 04/06/2008 - 23:06

Your firewall is already providing perimeter security but you may still provide another layer of security protection in your edge router facing internet, I personally use the examples provided in these links.




thotsaphon Sun, 04/06/2008 - 23:56

Hi Venkat,

Actually your firewall already provides functions to protect a outside interface.As you know,Traffics originating from inside should be allowed by a firewall. It will deny all traffics originating from outside unless you want to allow them.One thing when you enable IOS firewall on a router you need to manually configure an acl to deny traffics from outside-to-inside.

Hopes this helps


Lavanholy Mon, 04/07/2008 - 01:35

Hi Thot,

Thanks a lot for the info.

Best Regards,


Lavanholy Mon, 04/07/2008 - 01:34

Hi Jorge,

Thanks for the info.It helped me a lot.

Best Regards,



This Discussion