On 2 Dec 2015, at 10:02, Nathan Ward wrote:

I have tested similar topologies in anger and haven’t found that the benefit (which is fairly small) is worth it for the added complexity.

One benefit is that if there's need to block/alter a particular response (say, for a botnet C&C), there's a centralized place to do it.

Logical functional bulkheading is also quite useful from an availability perspective.

-----------------------------------
Roland Dobbins <[email protected]>
_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to