Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Quick Config Question


Just have a quick question. What is the best practice for placement of a firewall. In front of the router or behind it. Is this a matter of security preferrence? Right now we have it setup router, to firewall to LAN. Working fine but don't know really if there is the "right" way.


Cisco Employee

Re: Quick Config Question

This is a pretty loaded question and I will try to keep my answer simple.

Most people have a router connecting to their Service Provider. This router is usually with some access-lists to perform a first level of filtering. It could also run the Context Base Access Control (CBAC) feature, which would make it a bit more secure. This router in turn connects to the outside interface of the FW, which in turn usualy connects to an internal router but if you have only one user subnet, connecting the segment to the FW is a non issue.

In short, very few people have their FW directly to connected their SP or as you say in front of their router.

Hope this helps,

Harold Ritter
Sr. Technical Leader
CCIE 4168 (R&S, SP)
México móvil: +52 1 55 8312 4915
Cisco México 
Paseo de la Reforma 222 Piso 19
Cuauhtémoc, Juárez
Ciudad de México, 06600
CreatePlease login to create content