I am about to buy 2 pix 515's
setting up a 3 teired dmz
internet
app
corp
my question is instead of using 1 pix with multiple interfaces for dmz's we are using 2 pix each with 3 interfaces
heres the Question
is it better practice to have the 2nd pix(internal) plugged into the switch hanging off the firewall or directly into the 3rd firewall interface ie:
Internet router -> PIX1 -> dmz1switch -> pix2
OR
Internet router -> pix1 >int1 = dmz1switch /int2 = pix2 -> dmz2switch
Iknow I have posted something like this before but there is NO way my company will go with the easier single FW config so here goes nothing
thanks
setting up a 3 teired dmz
internet
app
corp
my question is instead of using 1 pix with multiple interfaces for dmz's we are using 2 pix each with 3 interfaces
heres the Question
is it better practice to have the 2nd pix(internal) plugged into the switch hanging off the firewall or directly into the 3rd firewall interface ie:
Internet router -> PIX1 -> dmz1switch -> pix2
OR
Internet router -> pix1 >int1 = dmz1switch /int2 = pix2 -> dmz2switch
Iknow I have posted something like this before but there is NO way my company will go with the easier single FW config so here goes nothing
thanks