[Webinar] Streamline your web hosting managementRegister Today

x
?
Solved

VPN failover on switch or on FW

Posted on 2014-12-15
6
Medium Priority
?
132 Views
Last Modified: 2014-12-18
I need feedback on the preference to implement VPN failover on a layer 3 switch or on a FW. Basically, I will have a layer 3 switch connecting to a primary MPLS connection and the Internet as the VPN backup. My question is which scenario is best practice: 1 or 2 (see below)

scenario 1:
internet<-->fw<-->3560x<-->internal
                                |
                              MPLS CE router

scenario 2:
internet<-->fw<-->3560x<-->internal
                     |
            MPLS CE router
0
Comment
Question by:leblanc
  • 4
  • 2
6 Comments
 
LVL 21

Expert Comment

by:netcmh
ID: 40501423
What is your FW? Where is the VPN configured? I would go with the FW handling your VPN failover.
0
 
LVL 1

Author Comment

by:leblanc
ID: 40501843
I am still shopping for FWs. But it will be between a Fortinet and a Juniper. So if i understanding correctly, scenario 2 is the prefer way? Thanks
0
 
LVL 21

Accepted Solution

by:
netcmh earned 2000 total points
ID: 40502435
I have an ASA then a FG then my L3. I can do a VPN split on either the ASA or the FG. I'd choose the ASA as it's efficient and designed to handle a variety of VPNs.
0
Managing Security Policy in a Changing Environment

The enterprise network environment is evolving rapidly as companies extend their physical data centers to embrace cloud computing and software-defined networking. This new reality means that the challenge of managing the security policy is much more dynamic and complex.

 
LVL 1

Author Comment

by:leblanc
ID: 40502992
So your ASA is connecting to the main WAN connection and the Internet connection and from the L3 switch, you just have a default route pointed to the ASA. Correct?
0
 
LVL 21

Assisted Solution

by:netcmh
netcmh earned 2000 total points
ID: 40503122
Correct. the default route is pointed to the ASA.
0
 
LVL 21

Expert Comment

by:netcmh
ID: 40506856
Thanks for the grade. Good luck.
0

Featured Post

Firewall Management 201 with Professor Wool

In this whiteboard video, Professor Wool highlights the challenges, benefits and trade-offs of utilizing zero-touch automation for security policy change management. Watch and Learn!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Stuck in voice control mode on your Amazon Firestick?  Here is how to turn it off!!!
In this article, WatchGuard's Director of Security Strategy and Research Teri Radichel, takes a look at insider threats, the risk they can pose to your organization, and the best ways to defend against them.
When cloud platforms entered the scene, users and companies jumped on board to take advantage of the many benefits, like the ability to work and connect with company information from various locations. What many didn't foresee was the increased risk…
How to fix display issue, screen flickering issue when I plug in power cord to the machine. Before I start explaining the solution lets check out once the issue how it looks like after I connect the power cord. most of you also have faced this…
Suggested Courses

590 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question