<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firewall to replace VLANs on a switch? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firewall-to-replace-vlans-on-a-switch/m-p/5282672#M1120640</link>
    <description>&lt;P&gt;Friend Firepower not give you as much as SW, firepower have little number of port,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But if you have few device then sure you can connect all device to firepower and use BDI between port.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This make traffic between device allow and can also use FW to access internet.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
    <pubDate>Fri, 18 Apr 2025 09:58:14 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2025-04-18T09:58:14Z</dc:date>
    <item>
      <title>Firewall to replace VLANs on a switch?</title>
      <link>https://community.cisco.com/t5/network-security/firewall-to-replace-vlans-on-a-switch/m-p/5281531#M1120610</link>
      <description>&lt;P&gt;High Level Overview of my network: Cisco 9400 at campus core, 9300s at four smaller branch schools. OSPF routing to our ISP who routes internal traffic directly to the correct building and external traffic to internet. All of these links are working fine.&lt;/P&gt;&lt;P&gt;Each location switch has 5-10 VLANs defined with inter-vlan routing enabled and ACL's controlling how traffic flows between them. This is also working fine but I am tired of command-line ACLs that are a PITA to construct, maintain, adjust and log.&lt;/P&gt;&lt;P&gt;Here is my wish: Can I get a Cisco Firewall at each location to make the VLANS actually live on the firewall instead of the switches themselves, then manage the ACLs on the firewall. This way they will be easier to manage and will be stateful.&lt;/P&gt;&lt;P&gt;If so, what would be the smallest (cheapest) model that can do this...as a test in my smallest school with the least amount of traffic...so that i can learn how to configure and maintain before trying to get a project budgeted for this functionality at all locations.&lt;/P&gt;&lt;P&gt;Thanks in advance for any recommendations.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 12:04:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-to-replace-vlans-on-a-switch/m-p/5281531#M1120610</guid>
      <dc:creator>darinheilman</dc:creator>
      <dc:date>2025-04-15T12:04:38Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall to replace VLANs on a switch?</title>
      <link>https://community.cisco.com/t5/network-security/firewall-to-replace-vlans-on-a-switch/m-p/5281557#M1120611</link>
      <description>&lt;P&gt;There are several factors that can impact the appliance model that you select:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Throughput requirements&lt;/LI&gt;
&lt;LI&gt;Threat features that will be used (IPS, Malware, URL Filtering)&lt;/LI&gt;
&lt;LI&gt;Size of the Access Control Policy (ACP). More specifically, the Number of Access Control Entries (ACEs)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If the above are minimal, then even the &lt;A href="https://www.cisco.com/c/en/us/products/collateral/security/firepower-1000-series/datasheet-c78-742469.html" target="_self"&gt;1010&lt;/A&gt; will be sufficient as that model supports up-to 60 VLANs/Subinterfaces. However, that appliance has been out for a while so it is probably better to go with the newer, &lt;A href="https://www.cisco.com/c/en/us/products/collateral/security/firewalls/secure-firewall-1200-series-ds.html" target="_self"&gt;1200&lt;/A&gt; series.&amp;nbsp;&lt;/P&gt;
&lt;DIV id="bodyDisplay_3" class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;
&lt;DIV class="lia-message-body-content"&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Tue, 15 Apr 2025 13:09:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-to-replace-vlans-on-a-switch/m-p/5281557#M1120611</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2025-04-15T13:09:19Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall to replace VLANs on a switch?</title>
      <link>https://community.cisco.com/t5/network-security/firewall-to-replace-vlans-on-a-switch/m-p/5281562#M1120613</link>
      <description>&lt;P&gt;as a test device in my smallest school....yeah, just minimal.&amp;nbsp; The only thing i want to initially use is ACL constructions and monitoring.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 13:14:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-to-replace-vlans-on-a-switch/m-p/5281562#M1120613</guid>
      <dc:creator>darinheilman</dc:creator>
      <dc:date>2025-04-15T13:14:18Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall to replace VLANs on a switch?</title>
      <link>https://community.cisco.com/t5/network-security/firewall-to-replace-vlans-on-a-switch/m-p/5282672#M1120640</link>
      <description>&lt;P&gt;Friend Firepower not give you as much as SW, firepower have little number of port,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But if you have few device then sure you can connect all device to firepower and use BDI between port.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This make traffic between device allow and can also use FW to access internet.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 18 Apr 2025 09:58:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-to-replace-vlans-on-a-switch/m-p/5282672#M1120640</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-04-18T09:58:14Z</dc:date>
    </item>
  </channel>
</rss>

