WatchGuard Firebox III 1000 and Nokia IP130

Posted on 2005-04-22
Last Modified: 2011-09-20
WatchGuard Firebox III 1000 and Nokia IP130

Currently I have a WatchGuard Firebox III 1000.  What I need to do is drop a Nokia IP130 SSL VPN appliance into my network

I know someone is probably wondering why I am adding the Nokia VPN appliance when the WatchGuard Firebox offers a VPN solution.  Well the reason is that we are in health care so I need the most secure tunneling so I choose SSL over IPsec.

What I am hoping for is someone with either direct experience or just over all skills to give me some help; insight or direction has to how to do this.
Question by:dclima
    1 Comment
    LVL 7

    Accepted Solution

    SSL via IPSec..?

    Health care, finance or any other data-sensitive industry..  that seems like overkill to me.

    If you're determined to do that -- just think through the connections and I suspect you'll answer your question for yourself.  

    IPSec is generally site to site (office to office)  -- so something establishes an IPSec tunnel to your existing Firebox.  (be it either an application on the 'client' machine.. or another FireBox servicing an office, yes?)

    IPSec encryption is generally "more than sufficient".  You've go to consider where the traffic originates from and where it is destined.  If you are using software on PCs -- and they land the session at your Fire 1000, you've got to physically secure all the ethernet BEHIND the firebox to make this effective.

    Putting SSL into a strong encryption/authentication tunnel is redundant.

    Sure, the defense in depth argument can be applied -- and if you have the time and money -- knock yourself out.

    Just pay attention to where the traffic gets encrypted and de-crypted, eh?

    -- Scott.

    Featured Post

    Highfive Gives IT Their Time Back

    Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

    Join & Write a Comment

    Have you ever set up your wireless router at home or in the office to find that you little pop-up bubble in the bottom right-hand corner of Windows read "IP Conflict - One of more computers on the network have been assigned the following IP address"…
    Enterprise networks where VoIP phones have been deployed frequently use port configurations that allow both a computer and an IP phone to be plugged into the same switch port but use different VLANs. On Cisco equipment I'm referring to the "native V…
    This video discusses moving either the default database or any database to a new volume.
    Excel styles will make formatting consistent and let you apply and change formatting faster. In this tutorial, you'll learn how to use Excel's built-in styles, how to modify styles, and how to create your own. You'll also learn how to use your custo…

    754 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    17 Experts available now in Live!

    Get 1:1 Help Now