Technical Q for you and an opinion
At the moment, we basically have a PIX that is acting almost as a proxy&we have a private fully router IP network that all site connect into and all traffic passes through the central pix&The pix has a huge access list that blocks all traffic to the web except for a white list of IPs for certain finance sites etc
Have now had it put to us that another business unit (about 30 sites) now wants these restrictions implemented for them but they also need other sites opened up that the other businesses cant access&so effectively I have 4 units (retail Chains)&2 are unrestricted and the other two will have separate restrictions
Im sure with enough tinkering, a pix could be set to do this easily enough and the pix is hosted so the firewall guys can do it, however, surely this is an ideal scenario for ISA server or a proxy server of some sort yes? I mean, is there going to be performance issues with the PIX asking it to do this much filtering constantly, and the maintenance must be a nightmare or am I off and this is perfectly OK?
I want to get my hands on ISA server and of course play, but I dont want to steer the company into an unnecessary cost if you think that the pix is capable of this. Keep in mind that its servicing around 100 sites currently with an expected additional 50 in the next couple of years&I know ISA can deal with this and its no longer a huge expense that I thought it might have been&.
Any quick advantages/disadvantages that you can see with this dont spend too much time I just need to have a case J
Start Free Trial