cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
647
Views
0
Helpful
5
Replies

IPS design

chiangfong
Level 1
Level 1

I have 2 unit ASA 5520 with AIP-SSM-20 for front-end and 2 units ASA5520 with AIP_SSM-20 for back-end.I also have 2 units catalyst 6509. How should my design looks like.

5 Replies 5

rhermes
Level 7
Level 7

You need to provide much more detail on the goals your design is trying to achieve.

Are the asa pairs for reduntancy?

What do you mean front-end and back-end, to what?

What networks feed into and out of this hardware?

Yes. Pairs of ASA is for redundancy. Front end mean to internet edge.Back end means internal network.

ASA pairs for redundancy makes sence, but I do not understand why you are using two sets of firewalls? what is between these two ASA pairs?

Between these two ASA pairs is a pair of catalyst 6509. The internal network is purely flat network. Do i need two pairs of ASA?

Thanks.

It all depends on what you are trying to accomplish and what features you are using in each ASA. The outside ASA, as a firewall can host serveral inside networks (limited by the number of interfaces in the ASA) each netowrk can have a different firewall policy assigned. If that meets your firewall needs, then you might not require a second set of ASAs.

You have not provided enough network requirements detail to even make an guess of what you need.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: