Which is better an inline IPS deployed inside or outside the firewall ?
An inline IPS inspects payload information of the packets, hence, will require CPU cycles to accomplish this information. In such a scenario minimising the network traffic to the input of an IPS should be the call. Therefore, deploying an inline IPS behind the firewall is the right approach. Let the IPS secure your network and application instead of processing the packets which firewall can block in its external interface.
Related Questions
- Are RWTC volunteers deployed to national disaster sites or to disasters outside of the Chapters service area?
- Can you publish Oracle CM SDK-based content outside of the firewall and still get good performance?
- Does Firewall, IPS, and Application Firewall good enough to stop Malware infection to my website?