Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

VPN design : VPN + existing firewall

our company currently has an existing firewall and I'm trying to add a VPN concentrator device in our network. I know I could either place the Concentrator parallel to the firewall or place it on the DMZ.

I would like to know how you guys are implementing your VPN solution if it's seperate from your firewall or any recommendation.

I somehow feel that putting it on the DMZ is more secure but then it's going to be difficult to implement since I'm using Raptor and I don't think it's capable of using more advanced routing protocols...

Any suggestions would be greatly appreciated!

New Member

Re: VPN design : VPN + existing firewall

Well, you can do it either way, since the IPSec traffic from the outside interface of the VPN concentrator and the Internet will be encrypted anyway, the firewall wont be able to do any thing useful from a filtering perspective. However, having the VPN concentrator located on a DMZ on a PIX you could do some denial of service attack prevention.

hope this helps

CreatePlease login to create content