Re: about vlan ?

From: Greg Hennessy (spamcatcher@example.com)
Date: 02/27/03


From: Greg Hennessy <spamcatcher@example.com>
Date: Thu, 27 Feb 2003 21:59:10 +0000

On 27 Feb 2003 13:45:49 -0800, brian_dell3@yahoo.com (brian) wrote:

>why would one need to configure vlan(s) in a firewall ? eg one can
>configure vlans on checkpoint firewall. but what is the whole point of
>setting vlans.

Because using dot1q beats the hell out of handling a lot of discrete
interfaces.

>
>the individual interface (each with its own IP address) is a network
>and like vlan itself. the firewall routes traffic between these
>interfaces (networks). traffic from one interface cannot go to
>another interface unless configured or allowed by the rules in the
>firewall.
>so why would one need to configure vlans on the interfaces ?

Combined with private VLANS on the switch its a lot more efficient and much
easier to manage.

A firewall with a Gig-E trunked handoff can potentially handle *way* more
discrete subnets than by using dedicated interfaces per network.

greg

--
$ReplyAddress =~ s#\@.*$##; # Delete everything after the '@'
Angels live, they never die.Apart from us,behind the sky
They're fading souls who've turned to ice.So ashen white in paradise


Relevant Pages

  • Re: router and adsl?
    ... Most firewall vendors have boxes with 3 interfaces. ... choice if you have a limited budget and arenīt too paranoid. ... >> network, but not with the other company. ...
    (microsoft.public.win2000.security)
  • Re: Recommend multi port ethernet adapter?
    ... |>network adapters. ... That doesn't really work (with CISCOish VLANs, ... it's possible to get dual port Intel ... we've got one in a firewall I help look after. ...
    (RedHat)
  • Re: Help Broadcasting a UDP packet on the LAN:URGENT
    ... network interfacethey should be using to do this. ... The current code binds to each of the interfaces and blats out a packet, ... I've been working with Bruce on this and there are parts that still worry ... Interactions with VLANs, for instance. ...
    (freebsd-net)
  • Re: router and adsl?
    ... so do you know any specific firewall ... >Use a firewall with 3 interfaces, ... >> network, but not with the other company. ... >> (i'm thinking put like a linksys router between the two, ...
    (microsoft.public.win2000.security)
  • Summary of answers for VAP routers/switches/firewalls (was Re: Routers, Switches, and Firewall testi
    ... That is review the configuration of the system itself (both the OS ... That's also where Algosec's Firewall Analyser ... network analyser on the other side. ... you actually need to do (Interfaces) x tests. ...
    (Pen-Test)