Re: Configuring routing protocol on FW I don't think you will find anything useful on Cisco site about why not to use Dynamic routing in firewalls as this is one of the selling points that Cisco use with there firewalls about how easy to add to a dynamic routing system. With regards to Dynamic Routing on the Firewall, I would not place on any firewall that is an Internet Gateway, I would consider placing only on firewalls that are internal, or used with an MPLS cloud to encrypt your traffic over the MPLS network. I know some places that actually place the default gateway on there Internet Firewall to point inwards so you have to have specific routes pointing to the Internet to be able to make a connection to it. Search with Google on Firewall Best Practices and it has links to cisco and sans regarding firewall best practices, there may be something in the docs that it references that is suitable. |