|
Posted by Sharky on October 1, 2007, 7:28 pm
If you were Registered and logged in, you could reply and use other advanced thread options
yvette.ye@gmail.com wrote:
>Hello...I am working on a project to allocate some protection to
>segregate the Data-center A from the rest of user community. and there
>are some requirements:
>1) this data-center A do not have internet connection directly, but it
>can access the internet via another data-center B.
>2) each server in data-center A will be access from the user community
>only specific ports/protocols open.
>3) each server in data-center A will be fully open to data-center B.
>4) ideally, the IP address of each server in data-center A will not be
>changed after put this internal firewall.
>5) the servers are Windows 2003 for file server, printer server,
>exchange server, SQL server, Web server and the regional domain
>controller (DC).
>6) the main DC and Exchange are located in data-center B.
>7) the data-center are split into 2 networks, one for production, the
>other is QA.
>8) we have no direct controll on data-center B.
>
>My questions is that: what kind of Cisco product can achieve this
>request?
Cisco ASA - adaptive security appliance
http://www.cisco.com/en/US/products/ps6120/products_data_sheet0900aecd802930c5.html
You could just get a PIX firewall but the ASA gives you the option of
IPS, VPN and more.
I agree with CosmicV on Cisco's status as a firewall provider, and
unless you are a VERY Cisco-centric organization, I'd suggest
broadening your search. My recommendation would be one the Secure
Computing Sidewinder appliances
http://www.securecomputing.com/index.cfm?skey=20
|