204
In a separate DMZ
(Figure 20.5)
Figure 20.5: VPN Deployment Scenario 5
Benefits
The firewall can protect the Security Gateway
Internet connectivity does not depend on the Security Gateway
The firewall can inspect and log plaintext from the VPN
Drawbacks
Special routes need to be added to the firewall
Support for roaming clients is very hard to achieve, since the firewall
will not know to route through the Security Gateway in order to
reach the VPN clients with moving IPs
Incorporated in the Firewall
(Figure 20.6)
Benefits
The firewall can protect the Security Gateway subsystem
The firewall can inspect and log plaintext from the VPN
Supports roaming clients
D-Link Firewalls User's Guide
Chapter 20. VPN Basics