[fw-wiz] Multiple small switches vs. a single big one; Granularity of control

From: Shimon Silberschlag (shimons_at_bll.co.il)
Date: 02/29/04


To: <firewall-wizards@honor.icsalabs.com>
Date: Sun, 29 Feb 2004 16:48:25 +0200

Note to moderator: I know one of these subjects has been raised in the past
on the list, but I think technology changes make it deserving another look.

When designing a new internet architecture, we are debating the use of
either a physical switch per segment, as was traditionally recommended by
the majority of readers on this list, and using a big switch combined with
an on-switch FW that controls traffic down to a port granularity (e.g. the
Cisco FWSM enclosed in the 6500 switch).

What would be the current group recommendations WRT to such a setup, taking
into account that the usual "don't trust VLANS to separate your segments" is
mitigated by using the FWSM to enforce the separation policy?

On a related issue, do the granularity of control usually stops at the
segment level, meaning do you allow unchecked traffic between the servers on
a segment, or should we opt for server level control, managing both inter-
and intra segment communications?

TIA,
Shimon Silberschlag

+972-3-9351572
+972-51-207130

_______________________________________________
firewall-wizards mailing list
firewall-wizards@honor.icsalabs.com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • Re: Wish to network my home computers but dont know Jack about it
    ... So a computer network may have 4 computers on one segment of wires, ... You can think of a hub ... get a hub instead of a switch. ...
    (Debian-User)
  • RE: Controling Segment Contents in TCP Stream
    ... How about controlling telnet via Expect? ... I think Expect would be fast enough to have telnet send "USER " as a single segment, then have your expect script sleep for n seconds, then send the rest. ... Controling Segment Contents in TCP Stream ... I am looking for a simple tool that I can use to control how TCP data ...
    (Pen-Test)
  • Re: Strange VLAN / DHCP / IP issue...
    ... SuperScope on the DHCP Server. ... Superscope are part of the same "physical segment". ... Just a guess, but, your Switch ports may be statically set to a certain ...
    (microsoft.public.windows.server.networking)
  • Re: spanning tree - looping basic question
    ... Segment B ... Now if Host A on Segment A wants to communicate with Host B of Segment ... the packet goes to Switch A. ... either B will complain, shut down a port or 2 and break the loop, or merrily ...
    (comp.dcom.sys.cisco)
  • Re: 3 segment wireless network
    ... can't see each other because the wireless part of the wireless router ... that strange, because if that were the case, why can it switch packets ... All of the other hardware is just bridges and hubs. ... in each segment can't see each other in My Network Places? ...
    (microsoft.public.windowsxp.network_web)