Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

VPN Concentrator Location

I'm implementing a VPN 3005 and I have a pix. Where would I place the VPN 3005 in regards to the PIX? VPN 3005: external int public and internal int private? external int to pix dmz and internal to private ? or both to dmz ports on the pix? Any suggestions is appreciated. Thanks.

New Member

Re: VPN Concentrator Location

I generally place the 3005 in parallel with the firewall. External int of 3005 on same network as external interface of firewall. Internet int on same network as internet int of firewall.

This allows you to operate the VPN even in the event of a PIX failure. For the more paranoid, placing the 3005 on a DMZ interface off the PIX is nice, as long as you have a routable subnet there...

It's really a metter of preference I'd say. If you place the 3005 in parallel, you can do some hardening on the internet router via an access-list to help protect the 3005 from port scans and eventual attacks.

hope this helps!

mike kantowski


Re: VPN Concentrator Location

Just a note of agreement. Parallel is the way to go. I ave been running that for about 6 months with no major problems although I am graduating to the 515r from a 506 and will place the 506 in front of the concentrator now.