08-09-2017 02:03 PM
Keeping in mind proper best practice for setup/design of Cisco Expressway Cluster creation, we are currently in the process of building entirely new Expressways (E and C). Our current setup is such that the external facing Expressway E is going through our DMZ. We are working with a contractor who instead recommends setting this up with a direct connection to the outside internet switch. Has anyone used a similar design, and if so, is this proper from a security standpoint? Any feedback would be greatly appreciated. Thanks.
08-09-2017 11:10 PM
Here are my thoughts on the preferred order of placement options for the Expressway appliances, assuming you are using VMWare here and not the "physical" appliance versions:
I have also seen deployments that put the EXP-E LAN#2 behind an internet DMZ with one to one NAT and put LAN#1 on the voice network where the EXP-C lives. I do not recommend this approach as if the EXP-E were compromised, an attacker would gain access to the inside of your network. At minimum, keep a firewall between the EXP-C and the EXP-E.
I hope this helps.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide