Firewall−Based VPN
The very same issues exist here as with routers. One needs to have compatible (preferably the
same vendor's) firewalls at each location. Mobile users or telecommuters must have compatible
VPN software. Firewalls are always potential bottlenecks, so asking them to perform VPN
encryption can adversely affect all other access to your network. Here again, there is no substitute
for traffic analysis. We only recommend this solution for small networks where the traffic through the
firewall can easily be handled by the firewall hardware.