<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Router or Firewall for S2S VPN in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/router-or-firewall-for-s2s-vpn/m-p/133141#M47168</link>
    <description>&lt;P&gt;We are standing up a new data center and there is some disagreement about&amp;nbsp;whether the Firewall or the Router should host the IPSec VPN.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Security Team &amp;nbsp;suggests the Firewall for a few reasons (Logging being the biggest)&lt;/P&gt;&lt;P&gt;while the Networking Team would like to use the Cisco Router (Speed and ease being their reasoning.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone run into a similar situation? How would you recommend designing it?&lt;/P&gt;</description>
    <pubDate>Thu, 15 Dec 2016 21:33:23 GMT</pubDate>
    <dc:creator>jsanford</dc:creator>
    <dc:date>2016-12-15T21:33:23Z</dc:date>
    <item>
      <title>Router or Firewall for S2S VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/router-or-firewall-for-s2s-vpn/m-p/133141#M47168</link>
      <description>&lt;P&gt;We are standing up a new data center and there is some disagreement about&amp;nbsp;whether the Firewall or the Router should host the IPSec VPN.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Security Team &amp;nbsp;suggests the Firewall for a few reasons (Logging being the biggest)&lt;/P&gt;&lt;P&gt;while the Networking Team would like to use the Cisco Router (Speed and ease being their reasoning.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone run into a similar situation? How would you recommend designing it?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2016 21:33:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/router-or-firewall-for-s2s-vpn/m-p/133141#M47168</guid>
      <dc:creator>jsanford</dc:creator>
      <dc:date>2016-12-15T21:33:23Z</dc:date>
    </item>
    <item>
      <title>Re: Router or Firewall for S2S VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/router-or-firewall-for-s2s-vpn/m-p/133149#M47169</link>
      <description>&lt;P&gt;Do you know bandwidth between sites?&lt;/P&gt;&lt;P&gt;Firewall datasheet will reveal it's VPN capabilities.&lt;/P&gt;&lt;P&gt;Compare firewalls page will give you good overview.&lt;/P&gt;&lt;P&gt;&lt;A title="https://www.paloaltonetworks.com/products/product-selection" href="https://www.paloaltonetworks.com/products/product-selection" target="_blank"&gt;https://www.paloaltonetworks.com/products/product-selection&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example 3050 vs 5060 = 500Mbit vs 4Gbit&lt;/P&gt;&lt;P&gt;&lt;A title="https://www.paloaltonetworks.com/content/pan/en_US/products/product-comparison.html?chosen=pa-5060,pa-3050" href="https://www.paloaltonetworks.com/content/pan/en_US/products/product-comparison.html?chosen=pa-5060,pa-3050" target="_blank"&gt;https://www.paloaltonetworks.com/content/pan/en_US/products/product-comparison.html?chosen=pa-5060,pa-3050&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2016 22:20:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/router-or-firewall-for-s2s-vpn/m-p/133149#M47169</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2016-12-15T22:20:28Z</dc:date>
    </item>
    <item>
      <title>Re: Router or Firewall for S2S VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/router-or-firewall-for-s2s-vpn/m-p/133196#M47172</link>
      <description>&lt;P&gt;I'd always go for firewall if you have enough resources there. And 'ease of use' argument goes in PA favour imo. Other benefits are security features, logging, traffic control by direction....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In any case; if you go for Cisco router make sure the decrypted traffic passes through your PA.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2016 07:33:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/router-or-firewall-for-s2s-vpn/m-p/133196#M47172</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2016-12-16T07:33:57Z</dc:date>
    </item>
    <item>
      <title>Re: Router or Firewall for S2S VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/router-or-firewall-for-s2s-vpn/m-p/133252#M47188</link>
      <description>&lt;P&gt;Really depends on what equipment you are using, as for a S2S I really would just recommend whatever can provide the most bandwidth. Reason being is that you probably have a static IP on all your sites correct? If so then your just as 'secure' running it through the Router with a good ACL as you are with the Firewall and as long as the equipment is on the same 'level' and roughly the same age the Router is always going to win looking at just bandwidth.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2016 13:50:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/router-or-firewall-for-s2s-vpn/m-p/133252#M47188</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-12-16T13:50:33Z</dc:date>
    </item>
  </channel>
</rss>

