• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 739
  • Last Modified:

Where to place a Cisco 5510 ASA with IPS?

Hi,

I need a solution to best place a cisco asa 5510 with IPS on my network. I have the WAN (Internet)  a DMZ (Proxy Server) and LAN (Domain) of another cisco asa 5520 for my network and would like to know where would be the best place to fit/place this new ASA 5510 with IPS.

Thanks
0
CBB
Asked:
CBB
1 Solution
 
tearmanCommented:
You might consider placing it between the WAN and your older ASA.  This would allow you to utilize the IPS more effectively in this case without having to completely uproot your older ASA (which I assume isn't an option).
0
 
CBBNet AdminAuthor Commented:
I don't want to remove the ASA 5520. I want to have both of  them on the network but I'm not sure where to place the ASA 5510 with IPS. Was thinking of placing the IPS either on the DMZ or LAN of the existing ASA 5520.... ?????
0
 
MikeKaneCommented:
You would want to place the ASA with IPS along the most used network channel that would need protection.    If you are protecting the internal network, then I would say place it between the existing ASA and the internal LAN to watch that traffic.    If it is for the DMZ  you would want to place it there.       Ideally, the IDS would be at the center point of the network so that the ASA with IDS would hand both zones for inside and DMZ allowing for maximum coverage.
0

Featured Post

Who's Defending Your Organization from Threats?

Protecting against advanced threats requires an IT dream team – a well-oiled machine of people and solutions working together to defend your organization. Download our resource kit today to learn more about the tools you need to build you IT Dream Team!

Tackle projects and never again get stuck behind a technical roadblock.
Join Now