<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Questions about deploying serverfarm FW in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/questions-about-deploying-serverfarm-fw/m-p/343224#M85938</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Currently, every server is behind trust zone, so I can't control traffic from trust user or server to server by FW.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have two options&lt;/P&gt;&lt;P&gt;&amp;nbsp;1 attach server farm switch to edge firewall&lt;/P&gt;&lt;P&gt;&amp;nbsp;2 deploy new FW in front of server farm switch&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which is more common way and is there any better reason to chose 2nd option than 1st?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 11 Aug 2020 09:01:27 GMT</pubDate>
    <dc:creator>yhlee1</dc:creator>
    <dc:date>2020-08-11T09:01:27Z</dc:date>
    <item>
      <title>Questions about deploying serverfarm FW</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/questions-about-deploying-serverfarm-fw/m-p/343224#M85938</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Currently, every server is behind trust zone, so I can't control traffic from trust user or server to server by FW.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have two options&lt;/P&gt;&lt;P&gt;&amp;nbsp;1 attach server farm switch to edge firewall&lt;/P&gt;&lt;P&gt;&amp;nbsp;2 deploy new FW in front of server farm switch&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which is more common way and is there any better reason to chose 2nd option than 1st?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2020 09:01:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/questions-about-deploying-serverfarm-fw/m-p/343224#M85938</guid>
      <dc:creator>yhlee1</dc:creator>
      <dc:date>2020-08-11T09:01:27Z</dc:date>
    </item>
    <item>
      <title>Re: Questions about deploying serverfarm FW</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/questions-about-deploying-serverfarm-fw/m-p/343330#M85958</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/103730"&gt;@yhlee1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Both of these ways are common solutions. In short: Option 2 is more secure but also more expensive while (obviously) option one is the opposite.&lt;/P&gt;
&lt;P&gt;This does not mean option 1 is bad, but in case of an attack from external and also in situations where the firewall may be too slow to handle every internal connection everything would be affected from an outage. So with option 2 you mainly distribute the load with reduces some risks about service continuity. Obviously buying a second firewall(cluster) with subscriptions and operating this one is more expensive than having only one firewall(cluster). The configuration itself you can have as secure as with two firewall(clusters). So mainly you have to decide for your company/your situation if the additional costs are worth reducing some risks or if you are ok with the disadvantages as long as you separate clients and servers.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2020 18:16:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/questions-about-deploying-serverfarm-fw/m-p/343330#M85958</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2020-08-11T18:16:36Z</dc:date>
    </item>
  </channel>
</rss>

