- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-29-2013 02:37 PM
If the PAN's in HA are perimeter FW's and IPS's how do you configure for Internal IPS Monitoring?
We'd like to be able to see internal IPS threats to our server farms sourced from workstations on the LAN's.
Is this scenario achievable with two HA PAN's?
Thanks in advance.
PotStirrer.
03-29-2013 04:08 PM
Personally I would suggest to use one set of hardware as outer firewalls/protection and another set of hardware as inner firewalls/protection.
Simply because if you get a DDoS on the outer firewalls the DMZ's connect there will basically go offline and with another hardware set as internal firewalls your internal network will continue to work even if the external firewalls are flooded.
This will also take in account regarding misconfigurations or for that matter hardware failure all together (where HA doesnt help).
But given that you cant afford to get a dedicated HA pair as internal firewalls a workaround can be to setup a different VSYS on your already existing set of PA HA pair.
That is VSYS1 is ExternalFW and VSYS2 is InternalFW. This will also make life easier the day you can afford a dedicated set of internal firewalls.
Now back to the VSYS... how you setup VSYS2 is up to you - simpliest way is to make it VWIRE and connect this between your internal router and the switch(es) your servers are connected to.
This is also how an IPS usually is setup as.
But if you want to make it an internal firewall (and not just IPS) I would configure it with L3-interfaces so you get a design such as:
Internet
|
ExternalFW - Internet-DMZ
|
Router - Clients
|
InternalFW
|
Server-DMZ
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!