scottdware
Technical User
Hello to all.
I am in the process of designing a new DMZ that will go into place in a new facility that our company is building. This facility will act as our "headquarters".
I plan on setting up IPSec VPN tunnels between our HQ and our 4 remote offices. Now, I have so far planned on having in the HQ:
2651XM for the T1 coming in from the Internet. A PIX 515E as the firewall.
So, my question is where should I have the IPSec VPN tunnels terminate? On the router (2651) or on the PIX. And if I have them terminate on the router (2651), then do I just need static routes in the router (2651) forwarding the remote office subnets to the pix's outside address (public), and access-lists on the pix permitting the remote offices' subnets.
Sorry if this sounds stupid, but I have never really setup a DMZ before from scratch by myself. Thanks
I am in the process of designing a new DMZ that will go into place in a new facility that our company is building. This facility will act as our "headquarters".
I plan on setting up IPSec VPN tunnels between our HQ and our 4 remote offices. Now, I have so far planned on having in the HQ:
2651XM for the T1 coming in from the Internet. A PIX 515E as the firewall.
So, my question is where should I have the IPSec VPN tunnels terminate? On the router (2651) or on the PIX. And if I have them terminate on the router (2651), then do I just need static routes in the router (2651) forwarding the remote office subnets to the pix's outside address (public), and access-lists on the pix permitting the remote offices' subnets.
Sorry if this sounds stupid, but I have never really setup a DMZ before from scratch by myself. Thanks