Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

IPS design

I have 2 unit ASA 5520 with AIP-SSM-20 for front-end and 2 units ASA5520 with AIP_SSM-20 for back-end.I also have 2 units catalyst 6509. How should my design looks like.

5 REPLIES
Gold

Re: IPS design

You need to provide much more detail on the goals your design is trying to achieve.

Are the asa pairs for reduntancy?

What do you mean front-end and back-end, to what?

What networks feed into and out of this hardware?

New Member

Re: IPS design

Yes. Pairs of ASA is for redundancy. Front end mean to internet edge.Back end means internal network.

Gold

Re: IPS design

ASA pairs for redundancy makes sence, but I do not understand why you are using two sets of firewalls? what is between these two ASA pairs?

New Member

Re: IPS design

Between these two ASA pairs is a pair of catalyst 6509. The internal network is purely flat network. Do i need two pairs of ASA?

Thanks.

Gold

Re: IPS design

It all depends on what you are trying to accomplish and what features you are using in each ASA. The outside ASA, as a firewall can host serveral inside networks (limited by the number of interfaces in the ASA) each netowrk can have a different firewall policy assigned. If that meets your firewall needs, then you might not require a second set of ASAs.

You have not provided enough network requirements detail to even make an guess of what you need.

172
Views
0
Helpful
5
Replies