Re: Vlan and Firewall

From: Somebody. (somebody._at_spamout.russdoucet.com)
Date: 09/19/05


Date: Mon, 19 Sep 2005 10:02:09 -0400


<Sid.lochan@gmail.com> wrote in message
news:1127114124.536497.113260@g43g2000cwa.googlegroups.com...
> Hi ,
>
> I know a little about firewalls. In my new company right now we have
> 150 systems including servers behind 198.168.165.0 IP range. We have a
> PIX 501/IOS 6.2-firewall which protects us. Now i have been told to
> create vlans for 5-6 departments as well as one vlan for servers with
> access limited to some vlans.We have 7 2950 series swtichs.
> I want to know that
> 1. Do i have to change setting in PIX too for Vlans.?Will firewall be
> able to see all diffrent VLANS under 1 ip range that is 192.168.165.0
> or i have to add some entries into it?(please also give EG
> configuration if i needed that).
>
> 2. IF i created vlans on switches then how i'll direct them to use
> Firewall to gain access to VPN and Internet.?
>
> Please Help me and also guide me about what configurations i shud use.
> Thanks in Advance.

You'll want to have a router in or behind your switch. It will route
traffic among the VLANs and out to your firewall on one network. Rather
than try to teach your firewall about the VLANs.

-Russ.



Relevant Pages

  • Re: Clueless firewall configuration ?
    ... The trend seems to be moving towards application based devices blurring the lines between routers, switches, firewalls, etc. ... Subject: Clueless firewall configuration? ... between the vlans (oh and we are a big production site that relies on ... You have an option to go with a managed service or an enterprise software. ...
    (Pen-Test)
  • Re: Clueless firewall configuration ?
    ... well ASA for Internet. ... these switches also provide routing modules, ... configuration mistake on the switch firewall connected ... between the vlans (oh and we are a big production site that relies on ...
    (Pen-Test)
  • Clueless firewall configuration ?
    ... cisco 6509 each with firewall blade in them. ... between the vlans (oh and we are a big production site that relies on ... ports would not be on the core switch but on the access layer switches ... You have an option to go with a managed service or an enterprise software. ...
    (Pen-Test)
  • net.link.ether.bridge.config effeciency for more then 2 interfaces?
    ... I'm trying to get a vlan based firewall working, but having a problem with ARP & DHCP not working well ... I've configured a local layer2 managed switch to have all vlans as tagged on port 1, and then configured two ports per vlan. ...
    (freebsd-net)
  • Re: IBM BladeCenter switch configurations
    ... switches. ... recommended configuration of the switches to be able to utilize at ... Consider BladeCenter switches as a normal Cisco switches. ... DATA-Only VLANs, and management traffic comes through management module. ...
    (comp.dcom.sys.cisco)