Firewall Wizards mailing list archives

RE: vpn end-point


From: Dean Davis <Dean.Davis () mbg-inc com>
Date: Thu, 18 Mar 2004 14:04:40 -0500

The Firewall for many reasons including:

1. Firewalls generally have more CPU-horsepower, enabling them to crunch
IPSEC calculations much faster; resulting in faster tunnels.
2. Added layer of security if the firewall resides behind the router
3. Reduces responsibilities of router to just route from serial interface
into the Ethernet interface
4. Stateful connectivity, although most routers support it.

 

Thanks,

Dean Davis, MCSE,MCDBA,CCNA,CNA,N+,Linux+

Sr. Network Engineer
MBG, Inc.
370 Lexington Avenue
New York, NY 10017
P. 212.822.4429
F. 212.822.4499
http://www.mbg-inc.com



-----Original Message-----
From: Shimon Silberschlag [mailto:shimons () bll co il] 
Sent: Wednesday, March 17, 2004 10:23 AM
To: firewall-wizards () honor icsalabs com
Subject: [fw-wiz] vpn end-point


Having to design multiple branches to main offices VPN, with the building
block on the branch side limited to a router and a firewall, what would be
your choice of ending the VPN tunnel, on the router or on the firewall?

Shimon Silberschlag

+972-3-9351572
+972-51-207130

_______________________________________________
firewall-wizards mailing list firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: