cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
768
Views
0
Helpful
1
Replies

VPN design : VPN + existing firewall

klorenzo
Level 1
Level 1

our company currently has an existing firewall and I'm trying to add a VPN concentrator device in our network. I know I could either place the Concentrator parallel to the firewall or place it on the DMZ.

I would like to know how you guys are implementing your VPN solution if it's seperate from your firewall or any recommendation.

I somehow feel that putting it on the DMZ is more secure but then it's going to be difficult to implement since I'm using Raptor and I don't think it's capable of using more advanced routing protocols...

Any suggestions would be greatly appreciated!

1 Reply 1

chriyoun
Level 1
Level 1

Well, you can do it either way, since the IPSec traffic from the outside interface of the VPN concentrator and the Internet will be encrypted anyway, the firewall wont be able to do any thing useful from a filtering perspective. However, having the VPN concentrator located on a DMZ on a PIX you could do some denial of service attack prevention.

hope this helps

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: