design question - AIP-SSM-10 in front of DB

Unanswered Question
Oct 22nd, 2009

I have an ASA 5510 and was considering putting my organization's database servers on their own interface. The reason I want to do this is to examine all traffic with my IPS sensor to/from my databases. Is it a "best practice" to do this? TIA

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Farrukh Haroon Sat, 10/24/2009 - 22:50

It is better to make a zone on the firewall and connect the switches/firewall using the switch. However you can always connect the server directly (as long as its using only ONE nic), but this is not a good design practice (especially in terms of scalability and manageability)

Regards

Farrukh

Actions

This Discussion