Hey guys, I need you guidance.
I have vpn devices and I see some were set to be directed through the fwl (asa 5510)
and some of course hit the dmz and then the LAN side of the vpn device got plugged into the
LAN side no direct routing through the ASA. Which is standard practice. I kind of like
the direct routing through the fwl. Not because it can scan it because obviously it cannot scan vpn traffic the the complex routing thru the fwl directing it the exact LAN next hop host you know what I mean vs having it plugged in to the entire LAN subnet for it to maybe if gotten hacked can go anywhere on the network. having it go thru fwl and be directed is that the better option when having vpn device configured into your network off the DMZ?
what is the best way and most secure? and any examples documenation out there by chance?