cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
260
Views
0
Helpful
2
Replies

How to design the security levels

new_networker
Level 1
Level 1

The design is:

1. Perimeter ASA

2. Front end servers (DMZ)

3. FWSM on Cat 6500

4. Back end servers - includes customer & transactional database (DMZ 1)

5. Back end connectivity to another site for transactional processing & response which then updates the backend servers customer & transactional database(INSIDE)

My query is whether point 5 should be given higher security level (INSIDE) than point 4 (DMZ1) or vice versa. What factors do I need to consider to decide on the security levels.

Regards.

2 Replies 2

bwilmoth
Level 5
Level 5

I think the INSIDE interface should be given high priority because the "outside" interface may sometimes be referred to as the "unprotected" interface and the "inside" interface is frequently referred to as the "protected" one.

The below URL may help you:

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a008069bf1b.shtml#intro

ajagadee
Cisco Employee
Cisco Employee

Hello New Networker,

Have you taken a look at the "Cisco Validated Designs", specifically around Security. This is an awesome place with a lot of good information.

http://www.cisco.com/en/US/netsol/ns744/networking_solutions_program_home.html

Regards

Arul

** Please rate all helpful posts **

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card