Cisco MPLS, Voice and Security Design - Advice Please

Soldato
Joined
17 Oct 2002
Posts
3,941
Location
West Midlands
Greetings if anyone could help me decide how best to go about the following it would be appreciated.

Im currently designing an MPLS deployment for a customer wishing to run voice, video and data on an MPLS network, they have 13 sites and 1 primary site as depicted in the diagram.

We shall be using SIP for incoming and outgoing voice plus an ISDN 30 for backup aswell as SRST at remote sites with redundant PSTN links.

The primary site will be running Call Manager, now im looking at having both an ISR and an ASA at the primary site for security sake and for terminating traffic on different devices but cant make up my mind whether it would function and whether i should have just the ASA the ISR or both.

My thinking is that if i run both, the router would have to sit on edge terminating the SIP Trunks and the firewall behind but

A: How to Terminate SIP Connections on the router then redirect them through the firewall

B: how to best make use of both products is keeping me awake at night!

Option B

The second method would be to put the router on the inside of the firewall and just have the firewall inspecting inbound/outbound traffic whilst terminating the SIP Trunks and VPNs on the ISR. This would be possible as the line into the primary site will be a 10mbit Ethernet connection.

Any recommendations welcome!

iptfw.jpg


iptfwB.jpg
 
It really depends on which ISR you're going for as terminating trunks and transcoding will probably eat the resources.

Personally I'd plump for option A, that way you're terminating all the VPN's on the ASA and letting it do most of the grunt with regards to the internet - it also makes the firewall the most external point on the network.

Your router can terminate trunks and transcode without taking a hit from VPN's and it's more secure as it's on the 'Inside' of the network.

(Though if you speak to my security team, they'll probably insist that you need to firewall the MPLS connection as well as your internet connection and need many, many firewalls and things....;))
 
Cheers for the reply, does make more sense to me to have the firewall on the inside.

I do prefer to have both devices and layer it.

:)
 
Back
Top Bottom