So....I want to hear some ideas with regard to changing things around on a network. I have one internet connection ( I cannot get two ). I know I will have a single point of failure at the edge and I'm ok with that because I can buy two of something to where I at least have a replacement.
I have an OC line, so an ASA at the edge to handle basic ACL rules and let it get hammered first. I'm not looking for the ASA to be a firewall, because friends don't let friends use ASA's for firewalls. It does ACL only. Then, it will come into two routers maybe or two edge firewalls. Then inside the edge firewalls into a DMZ and then to two external firewalls, then to internal core etc....
I have a single point of failure, I can't change that, but looking for the ideas for HA inside of that.
If you have questions, please feel free to ask and I will answer and update throughout the day. I will answer what I can....
I have an OC line, so an ASA at the edge to handle basic ACL rules and let it get hammered first. I'm not looking for the ASA to be a firewall, because friends don't let friends use ASA's for firewalls. It does ACL only. Then, it will come into two routers maybe or two edge firewalls. Then inside the edge firewalls into a DMZ and then to two external firewalls, then to internal core etc....
I have a single point of failure, I can't change that, but looking for the ideas for HA inside of that.
If you have questions, please feel free to ask and I will answer and update throughout the day. I will answer what I can....