Router or Firewall for S2S VPN

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Router or Firewall for S2S VPN

L0 Member

We are standing up a new data center and there is some disagreement about whether the Firewall or the Router should host the IPSec VPN. 

 

The Security Team  suggests the Firewall for a few reasons (Logging being the biggest)

while the Networking Team would like to use the Cisco Router (Speed and ease being their reasoning.)

 

Has anyone run into a similar situation? How would you recommend designing it?

3 REPLIES 3

Cyber Elite
Cyber Elite

Do you know bandwidth between sites?

Firewall datasheet will reveal it's VPN capabilities.

Compare firewalls page will give you good overview.

https://www.paloaltonetworks.com/products/product-selection

 

For example 3050 vs 5060 = 500Mbit vs 4Gbit

https://www.paloaltonetworks.com/content/pan/en_US/products/product-comparison.html?chosen=pa-5060,p...

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

I'd always go for firewall if you have enough resources there. And 'ease of use' argument goes in PA favour imo. Other benefits are security features, logging, traffic control by direction....

 

In any case; if you go for Cisco router make sure the decrypted traffic passes through your PA.

Cyber Elite
Cyber Elite

Really depends on what equipment you are using, as for a S2S I really would just recommend whatever can provide the most bandwidth. Reason being is that you probably have a static IP on all your sites correct? If so then your just as 'secure' running it through the Router with a good ACL as you are with the Firewall and as long as the equipment is on the same 'level' and roughly the same age the Router is always going to win looking at just bandwidth. 

  • 3070 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!