Quote:
It also depends on how many Simultaneous Users you will have on the vpn server. If your dmz has multiple high traffic servers then you decide that you want 1000 ppl to connect to your vpn, you are going to cause problems with collisions or response times. If your only going to have 100 or so VPN users then the DMZ would be a good place to add your vpn server. If you dont have a DMZ and dont want your server sitting outside the firewall, then you will need to add it behind the firewall, yet you will have to open the appropriate ports on the firewall for IPSec to negotiate. Some VPN Servers have slots which you can add T1 cards and place them directly next to the core router that way you arent consuming internet, dmz traffic on your Core I-Net connection.
Ummm... this is a completely separate issue and I'll leave it at the idea that it doesn't have much to do with placement, though it might have a bit to do with how you want to segregate your network segments.
Quote:
So again, it all depends on how your current network is layed out and where it would fit most appropriately and it would also be recommended to check with the VPN Server manufacturer to where they recommend their VPN Server on your network. Your only main concern should be that you do not want your internal network and the outside interface network on the VPN server to be on the same VLAN.
With my experience adding a Cisco VPN Concentrator parallel to the Firewall, I have never encountered a problem.
My experience seems to be that most VPN vendors don't have much of a clue as to placement of the server - as I've said, it tends to be a bit of a holy war, to a point.
Quote:
Assuming a common network topology consiting of a 3 legged firewall with internal network and DMZ, where would a vpn server be commonly placed? (VPN for remote users, not site-to-site)
To me, that says "small network with a couple hosts on the DMZ (www, ftp, ns, etc) and a firewall that segregates the Internet from both the DMZ and LAN, and the LAN and DMZ from each other." I'm not imaging some hugely complicated network with multiple VLANs, a load balanced or clustered firewall system with fully redundant links to the Internet" or anything even