JoeBloggssss
IS-IT--Management
Hi,
I have a quick question. To the best of my understanding, a VPN can be terminated at the edge router, firewall, or VPN appliance (Cisco Secure VPN Concentrator or Nokia device), I am currently aware all these devices are interporable as they confirm to standards for IKE and IPSEC phases, I have also read up on VPDN for dialup. My question is Cisco routers are perfered to Nokia devices as a more cost effective solution with enhanced routing and switching capabilites. I read that due to the nature of the IPSEC protocol is can not traverse a NAT device, so if I want VPN-1 to handle my vpns and act as termination points but have a router sitting in front of my enforcement module, how can I do this? What it the vpn design you guys usually implement, I assume you host VPN services with a DMZ?
I have a quick question. To the best of my understanding, a VPN can be terminated at the edge router, firewall, or VPN appliance (Cisco Secure VPN Concentrator or Nokia device), I am currently aware all these devices are interporable as they confirm to standards for IKE and IPSEC phases, I have also read up on VPDN for dialup. My question is Cisco routers are perfered to Nokia devices as a more cost effective solution with enhanced routing and switching capabilites. I read that due to the nature of the IPSEC protocol is can not traverse a NAT device, so if I want VPN-1 to handle my vpns and act as termination points but have a router sitting in front of my enforcement module, how can I do this? What it the vpn design you guys usually implement, I assume you host VPN services with a DMZ?