Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
Community Member

design question - AIP-SSM-10 in front of DB

I have an ASA 5510 and was considering putting my organization's database servers on their own interface. The reason I want to do this is to examine all traffic with my IPS sensor to/from my databases. Is it a "best practice" to do this? TIA

1 REPLY

Re: design question - AIP-SSM-10 in front of DB

It is better to make a zone on the firewall and connect the switches/firewall using the switch. However you can always connect the server directly (as long as its using only ONE nic), but this is not a good design practice (especially in terms of scalability and manageability)

Regards

Farrukh

141
Views
0
Helpful
1
Replies
CreatePlease to create content