cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
743
Views
5
Helpful
4
Replies

Need Suggestion On Best Practice Solution

pauzi123@
Level 1
Level 1

Hello,

Im currently in midst of optimizing site network that have more than 4100 users (currently). I would like know whether is it better to put:

  1. Firewall in-front of router OR
  2. Router in-front of firewall

My Firewall is ASA 5508-X (FirePower)

My Router is Cisco 2911-HSEC+/K9

Currently the router is handling only NAT-ing. The memory utilization is 79%

I attached current overall drawing for the site.

1 Accepted Solution

Accepted Solutions

Leonardo Gama
Level 1
Level 1

Hi,

Considering your current topology and the fact that your ASA has far more horsepower than 2911, I would remove the 2911 from the topology (less point of failure) and let all routing and NAT with the firewalls, logically if you do not need any fancy feature from ISR routers.

Moreover I would insert a redundant 3850 switch with the second ASA.

Cheers.

View solution in original post

4 Replies 4

marce1000
VIP
VIP

  - Your keyword 'in-front of' is undefined because it can be explained in 2 ways; it's better to have the router at the real edge, and only let it  handle routing; you should handle NAT on the firewall to take advantage of using firewalling properties/actions  when doing NAT.

M.



-- ' 'Good body every evening' ' this sentence was once spotted on a logo at the entrance of a Weight Watchers Club !

Thank you for the information. What i mean by in front is, is better to put firewall or router first?

My current setup is firewall first having public IP, the router is connected at the firewall.

  - Check the remarks from Leonardo

M.



-- ' 'Good body every evening' ' this sentence was once spotted on a logo at the entrance of a Weight Watchers Club !

Leonardo Gama
Level 1
Level 1

Hi,

Considering your current topology and the fact that your ASA has far more horsepower than 2911, I would remove the 2911 from the topology (less point of failure) and let all routing and NAT with the firewalls, logically if you do not need any fancy feature from ISR routers.

Moreover I would insert a redundant 3850 switch with the second ASA.

Cheers.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: