cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
365
Views
0
Helpful
1
Replies

design question - AIP-SSM-10 in front of DB

snickered
Level 1
Level 1

I have an ASA 5510 and was considering putting my organization's database servers on their own interface. The reason I want to do this is to examine all traffic with my IPS sensor to/from my databases. Is it a "best practice" to do this? TIA

1 Reply 1

Farrukh Haroon
VIP Alumni
VIP Alumni

It is better to make a zone on the firewall and connect the switches/firewall using the switch. However you can always connect the server directly (as long as its using only ONE nic), but this is not a good design practice (especially in terms of scalability and manageability)

Regards

Farrukh

Review Cisco Networking products for a $25 gift card