design question - AIP-SSM-10 in front of DB

Unanswered Question
Oct 22nd, 2009
User Badges:

I have an ASA 5510 and was considering putting my organization's database servers on their own interface. The reason I want to do this is to examine all traffic with my IPS sensor to/from my databases. Is it a "best practice" to do this? TIA

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Farrukh Haroon Sat, 10/24/2009 - 22:50
User Badges:
  • Red, 2250 points or more

It is better to make a zone on the firewall and connect the switches/firewall using the switch. However you can always connect the server directly (as long as its using only ONE nic), but this is not a good design practice (especially in terms of scalability and manageability)




This Discussion