F
F
frolov4ynga2020-06-12 10:33:26
Computer networks
frolov4ynga, 2020-06-12 10:33:26

What is the best way to connect to the Internet?

Can you please tell me how to connect to the Internet in the local network? which option will be more secure (protected):
1. Connect through a Cisco 2600/2800 series router. We take out the Squid proxy server on Linux separately.

spoiler
5ee32f3d0a32c562894155.jpeg

2. Through a Cisco 2600/2800 series router. But the Squid proxy server on Linux between the router and the LAN.
spoiler
5ee32f4a36f57848779006.jpeg

3. Through the Squid proxy server on Linux.
spoiler
5ee32f53e9e4a939761356.jpeg

The proxy is deployed on a regular PC with two network cards. It is planned to access the Internet for users both with and without a proxy.

Answer the question

In order to leave comments, you need to log in

4 answer(s)
A
Andrey Barbolin, 2020-06-12
@dronmaxman

The first option is more correct.
Because
- you will have clients who do not need or do not fit, or do not work with a proxy, then they will go to the Internet through Cisco
- this option is the most reliable of the schemes you proposed, because. hardware solutions are more reliable than software, if something happens to the proxy, you just release everyone on the Internet through cisco.
- you get the separation of resources and you can serve them separately, you can organize a VPN on cisco
, etc. etc.

K
ky0, 2020-06-12
@ky0

It is better not to set a break in the proxy - network equipment is considered more reliable by default. And so - an additional point of failure.
In general, there is not enough information - how serious is fault tolerance needed? What's up with channel duplication? Is it necessary to provide for the possibility of upgrading the whole thing?

A
Artyom Varlamov, 2020-06-12
@Frontend777

The first one is better, but only in this situation!

C
CityCat4, 2020-06-12
@CityCat4

The third option is so-so - when falling, the piece of iron will rise faster than linux. The choice between the first two depends on how strong control is needed and what the proxy is for.
If the proxy is just to simplify the settings for accessing the tyrnet and do not care who goes where - you can also be the first. If you need access control - definitely the second.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question