< Back to LISTSERV archives

NETMAN@LISTSERV.EDUCAUSE.EDU


View:

:

[

|

Previous Message

|

Next Message

|

]

:

[

|

Previous Message

|

Next Message

|

]

:

[

|

Previous Message

|

Next Message

|

]

:

Proportional Font

LISTSERV Archives

LISTSERV Archives

NETMAN Home

NETMAN Home

NETMAN  2014

NETMAN 2014

Subject:

Re: 10Gbps+ firewalling solutions

From:

Kent Eitzmann <[log in to unmask]>

Reply-To:

The EDUCAUSE Network Management Constituent Group Listserv <[log in to unmask]>

Date:

Mon, 8 Sep 2014 02:03:26 +0000

Content-Type:

text/plain

Parts/Attachments:

Parts/Attachments

text/plain (26 lines)

Joe, 

1. Where do you currently have firewall appliances installed (i.e. - organization perimeter, per building, per department, data center(s), etc.) 
Most of our firewalls are at our distribution layer (Cisco 6807 VSS's) . These are multi-context ASA5585-SSP40's (routed), we provide contexts to individual depts. as requested,  and for other services we provide to campus. 

2. What size firewalls do have at each location? Do you have an HA design there as well?
The 5585-40's in each case are an active/standby pair. The HA pair is split between 2 locations alongside the VSS boxes. 

3. Do you firewall your wireless network? Why or why not?
Yes. Since we use private IP's for wireless we use them for PAT.

4. Do you firewall your residential network? Why or why not?
Yes. This is currently mostly for wireless and the need to PAT.

5. What is your firewall design for your data centers?
Pair of 5585-40's split between primary and backup datacenters.  

6. "Next-gen" firewalls are becoming a hot topic. Do you use the feature sets of the Next-Gen firewall beyond the IP ACL's? Do you restrict any outbound traffic?
Not currently
7. Do you use a username-based ACE deployment - such as Cisco ASA's "Identity Firewall" where ACE's are written based on active directory groups and usernames?
Not Currently

Kent Eitzmann

**********
Participation and subscription information for this EDUCAUSE Constituent Group discussion list can be found at http://www.educause.edu/groups/.

Top of Message | Previous Page | Permalink


Options

Log In

Log In

Get Password

Get Password


Search Archives

Search Archives


Join or Leave NETMAN

Join or Leave NETMAN


Archives

2017
2016
2015
2014
2013
2012
2011
2010
2009
2008
2007
2006
2005
2004
2003
2002
2001
2000
1999
1998

ATOM RSS1 RSS2