If the PAN's in HA are perimeter FW's and IPS's how do you configure for Internal IPS Monitoring?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

If the PAN's in HA are perimeter FW's and IPS's how do you configure for Internal IPS Monitoring?

L1 Bithead

If the PAN's in HA are perimeter FW's and IPS's how do you configure for Internal IPS Monitoring?

We'd like to be able to see internal IPS threats to our server farms sourced from workstations on the LAN's.

Is this scenario achievable with two HA PAN's?

Thanks in advance.

PotStirrer.

1 REPLY 1

L6 Presenter

Personally I would suggest to use one set of hardware as outer firewalls/protection and another set of hardware as inner firewalls/protection.

Simply because if you get a DDoS on the outer firewalls the DMZ's connect there will basically go offline and with another hardware set as internal firewalls your internal network will continue to work even if the external firewalls are flooded.

This will also take in account regarding misconfigurations or for that matter hardware failure all together (where HA doesnt help).

But given that you cant afford to get a dedicated HA pair as internal firewalls a workaround can be to setup a different VSYS on your already existing set of PA HA pair.

That is VSYS1 is ExternalFW and VSYS2 is InternalFW. This will also make life easier the day you can afford a dedicated set of internal firewalls.

Now back to the VSYS... how you setup VSYS2 is up to you - simpliest way is to make it VWIRE and connect this between your internal router and the switch(es) your servers are connected to.

This is also how an IPS usually is setup as.

But if you want to make it an internal firewall (and not just IPS) I would configure it with L3-interfaces so you get a design such as:

Internet

|

ExternalFW - Internet-DMZ

|

Router - Clients

|

InternalFW

|

Server-DMZ

  • 1619 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!