Router or Firewall for S2S VPN

Reply
Highlighted
L0 Member

Router or Firewall for S2S VPN

We are standing up a new data center and there is some disagreement about whether the Firewall or the Router should host the IPSec VPN. 

 

The Security Team  suggests the Firewall for a few reasons (Logging being the biggest)

while the Networking Team would like to use the Cisco Router (Speed and ease being their reasoning.)

 

Has anyone run into a similar situation? How would you recommend designing it?

L7 Applicator

Re: Router or Firewall for S2S VPN

Do you know bandwidth between sites?

Firewall datasheet will reveal it's VPN capabilities.

Compare firewalls page will give you good overview.

https://www.paloaltonetworks.com/products/product-selection

 

For example 3050 vs 5060 = 500Mbit vs 4Gbit

https://www.paloaltonetworks.com/content/pan/en_US/products/product-comparison.html?chosen=pa-5060,p...

Enterprise Architect @ Cloud Carib www.cloudcarib.com
ACE (3.0, 5.0, 6.0, 7.0), PCNSE (6, 7), PCNSI
L5 Sessionator

Re: Router or Firewall for S2S VPN

I'd always go for firewall if you have enough resources there. And 'ease of use' argument goes in PA favour imo. Other benefits are security features, logging, traffic control by direction....

 

In any case; if you go for Cisco router make sure the decrypted traffic passes through your PA.

L7 Applicator

Re: Router or Firewall for S2S VPN

Really depends on what equipment you are using, as for a S2S I really would just recommend whatever can provide the most bandwidth. Reason being is that you probably have a static IP on all your sites correct? If so then your just as 'secure' running it through the Router with a good ACL as you are with the Firewall and as long as the equipment is on the same 'level' and roughly the same age the Router is always going to win looking at just bandwidth. 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!