We purchased a FWSM and external IPS 4255 to replace our existing external PIX525 and another vendors IPS. We currently have a 1 gig uplink to our main campus and the Internet. The PIX sits out front with the IPS behind it then our core 6513 campus router.
I have been reading about placement of the MSFC. We have a number of VLANs on our 6513 switch. They all talk to each other presently. I would like to add a DMZ to move certain services outside our internal network.
Trying to decide a few things.
Should we be using the inside or outside MSFC model? We have one uplink to our main campus and the Internet.
THe IPS placement. Our current IPS sits behind our external PIX. It only see incoming traffic that the firewall isn't blocking. Is there a means to route into the FWSM then out to the IPS and then back to our inside network? Or should we just place the IPS outside our network and inspect all traffic in and out.