cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1762
Views
0
Helpful
10
Replies

Security in Data Center

rahimbhamani
Level 1
Level 1

Well our organization is planning to implement security in Datacenter for Server Farm. Therefore we are purchasing ASA 5585-X series devices. I need your suggestion that how we can implement firewall b/w Core Switch and Server Farm switch

According to my suggestion:

1.      Firewall is in transparent mode (because all server gateways will be core switch)

2.      Ether channel between Core switch and Firewall and b/w Server farm switch and Firewall

3.      Interfaces b/w Core switch and Firewall and b/w Server farm switch and Firewall must be trunk

4.      Interfaces B/w Core switch and Firewall must be outside zone and b/w Server farm switch and Firewall must be inside zone.

5.      And ACL will be applied at Outside interface IN direction.

Suggestion is required.

10 Replies 10

Reza Sharifi
Hall of Fame
Hall of Fame

Rahim,

I am wondering, what you are trying to secure with the firewall.  Do you have multiple organizations connecting to you access switch in the server farm in different vlans?  If yes, ACLs on the router can block vlan communication. If it is all the same organization residing on the same switch, then what is the purpose of the firewall?

HTH

Reza

No, we dont connecting multiple organiztaions. We only want to secure Server Farm through ACLs by using firewall.And we dont want Core switch to use as a Firewall.

We only want to secure Server Farm through ACLs by using firewall.

Wow, that is a very pricey option.  A router with properly defined ACL will suffice.

But in future we also need to deploy IPS option and the said firewall has module for IPS.

But in future we also need to deploy IPS option and the said firewall has module for IPS.

And you position the ASA between your core switch and your server farm?

Yes.

Are you trying to establish a DMZ for your server farm? 

Well you can say that, all vlan are in different DMZ Zone.

Managing traditionnal ACLs can be a nightmare with dynamic protocols (ftp for instance, or protocols used by unified communications), a firewall will be easier for administration.

Hello

Our company is looking into implementing a DC firewall solution too. We're evaluating other firewall vendors that support full dynamic routing protocols as well as statefull packet inspection. I always thought of the ASA of just being a firewall first, not using any dynamic routing protocols on it.

  • Can the ASA 5585-x series support full dynamic routing protocols without any performance issues?
  • Does the ASA 5585-x contain a separate RE module?
  • What is the best practice for using the ASA as a DC firewall?