mercredi 25 mars 2015

How to design a right VPN connection for an organisation (Interconnected MPLS link or Individual FW)



Thanks in advance for your advice


We have to implement VPN connection for nearly 7 countries


Option 1 :


As we have private MPLS link to all 7 countries. It is been outsourced Third party.



  1. They provide VPN with 2FA with a extra cost. But challenge is it opens up access to all countries.

  2. Managed by Third party, Every change request depends on them

  3. Thinking that it might be challenge to manage in terms of security and compliance

  4. though we have a option of creating access list to restrict access to their respective countries. i beleive its challenge for security becuase some of the countries may be PCI compliant and do different projects.

  5. Is it possible to monitor through the local FW or IPS?


OPTION 2:



  1. Every country has their own FW(ASA or Fortigate)

  2. Can we create VPN in the respective FW? Is it advisable than VPN through MPLS?

  3. Is the VPN free for the Fortigate and ASA?. Is there any limitations?

  4. I believe its easy and have more control to implement VPN in the respective countries

  5. As they will have access only to the particular zone (country)

  6. It will be useful for future projects in terms of compliance.


As usual, please provide your highly valuable comments/answers/opinion. Which is the best way to go





Aucun commentaire:

Enregistrer un commentaire