Change Topology NGAF 20

rohmat_dsi Lv1Posted 25 Oct 2022 14:55

i want to change the existing network topology.
here I attach the topology


now I want to change the topology to something like the following, is there anything that needs to be set in the NGAF?

rivsy has solved this question and earned 10 coins.

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins, 20 coins of bounty and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

Last edited by rivsy 25 Oct 2022 15:54.

For the Public IP Area
1. IP address to the endpoint is based on the first router .
2. For this setup, Public Area will not be protected from threat, cannot be managed by NGAF and have security consent since connection is direct to the first router.
3. Static IP for the 3 router in the Public Area
4. Default gateway IP address same with first router

For the DMZ Zone
1. IP address of the server is based on the NGAF
2. Default gateway IP addresssame with first router

Is this answer helpful?
Robin Lv3Posted 07 Nov 2022 09:05
  
Your suggested diagram is not security efficient. You should not change it.
Snipe Lv2Posted 07 Nov 2022 08:54
  
Dont change your topology because the current is the recommended one.
kmrnliaqat Lv3Posted 05 Nov 2022 17:12
  

It is not a good  design proposal because other network doesn't have security.
Deorwine Lv2Posted 03 Nov 2022 11:01
  
Your current diagram is much better and it is recommended design.
Faisal P Posted 01 Nov 2022 13:23
  
You can refer to the document for very detailed steps to configure NGAF
Brooker Lv3Posted 01 Nov 2022 10:47
  
Recommended topology is your current design not the new
arjay Lv3Posted 01 Nov 2022 10:01
  
Much better that all traffics will pass through NGAF for filtering including the endpoint users
jetjetd Lv5Posted 01 Nov 2022 01:36
  
Stick with the old topology, all the traffic that goes in your network will go to the NGAF first. In your new topology some network is open and exposed in the internet which is dangerous.
nobitachou Lv2Posted 31 Oct 2022 20:22
  
The most of the configuration is on the router but it is all about IP Addressing.
babeshuka Lv3Posted 31 Oct 2022 19:06
  
Do not change your current setup. NGAF alone can do Server Protection and Lateral protection.

I Can Help:

Change

Moderator on This Board

11
7
5

Started Topics

Followers

Follow

1
3
5

Started Topics

Followers

Follow

0
4
5

Started Topics

Followers

Follow

67
20
3

Started Topics

Followers

Follow

3
14
3

Started Topics

Followers

Follow

1
137
3

Started Topics

Followers

Follow

Board Leaders