10-03-2008 03:37 AM - edited 03-11-2019 06:52 AM
The design is:
1. Perimeter ASA
2. Front end servers (DMZ)
3. FWSM on Cat 6500
4. Back end servers - includes customer & transactional database (DMZ 1)
5. Back end connectivity to another site for transactional processing & response which then updates the backend servers customer & transactional database(INSIDE)
My query is whether point 5 should be given higher security level (INSIDE) than point 4 (DMZ1) or vice versa. What factors do I need to consider to decide on the security levels.
Regards.
10-09-2008 01:47 PM
I think the INSIDE interface should be given high priority because the "outside" interface may sometimes be referred to as the "unprotected" interface and the "inside" interface is frequently referred to as the "protected" one.
The below URL may help you:
10-09-2008 01:56 PM
Hello New Networker,
Have you taken a look at the "Cisco Validated Designs", specifically around Security. This is an awesome place with a lot of good information.
http://www.cisco.com/en/US/netsol/ns744/networking_solutions_program_home.html
Regards
Arul
** Please rate all helpful posts **
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: