ISP/VLAN/Firewall Security Guys, This is not strictly a checkpoint issue but more of a secuirty concern. We have just changed to a new ISP which has now been delivered. However, our network engineer on site as patched the ISP internet feed into our DMZ on a sperate VLAN and from the VLAN patched to the external interface of our firewall, there is also a Cisco ASA connected to this VLAN for a joint venture project. My question is, would this be a valid configuration and is there any secure concerns? it seems to expose our DMZ although seperated by the VLAN. This is the first I have come across this kind of set-up, usually the internet feed is patched straight into the firewalls external interface. Would be grateful for any advise Andy |