[177816] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: Dynamic routing on firewalls.

daemon@ATHENA.MIT.EDU (Nicholas Oas)
Thu Feb 5 19:03:49 2015

X-Original-To: nanog@nanog.org
In-Reply-To: <FAE35F46-1B36-4372-A32B-67E07A8DFB3B@nerd-residenz.de>
From: Nicholas Oas <nicholas.oas@gmail.com>
Date: Thu, 5 Feb 2015 19:02:58 -0500
To: "Ralph J.Mayer" <rmayer@nerd-residenz.de>
Cc: "nanog@nanog.org" <nanog@nanog.org>
Errors-To: nanog-bounces@nanog.org

A router behind the firewall is nice too.
It insulates the firewall from direct end-user traffic.
It also makes for a cleaner cutover from one firewall to another. (Instead
of the edge getting stuck ARPs their perspective of the network remains
unchanged.)
It also allows for stateless ACLs on both ends of the firewall.


On Thu, Feb 5, 2015 at 1:49 PM, Ralph J.Mayer <rmayer@nerd-residenz.de>
wrote:

> Hi David,
>
> a router is a router and a firewall is a firewall.
>
> Especially a Cisco ASA is no router, period.
>
> A router in front of the firewall is my choice, it also keeps broadcasts
> from the firewall + can do uRPF.
>
>
> rm

home help back first fref pref prev next nref lref last post