<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: firewall and network segment question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firewall-and-network-segment-question/m-p/1450253#M640572</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, base on your diagram, it would be best to just have 1 firewall since you do not have a router/L3 switch in your internal network that can do the routing to 2 firewalls.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe your preference would be to route everything towards the VPN/ADSL connection?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you would like to route traffic towards 2 firewalls, ie: one for internet connection and the other for vpn traffic, then you would need to have a router/L3 switch to route the traffic accordingly as follows:&lt;/P&gt;&lt;P&gt;- Traffic towards the internet would have default route/default gateway configured towards the first firewall (for internet connectivity).&lt;/P&gt;&lt;P&gt;- Traffic towards the VPN would have specific routes (remote/HQ LAN subnets) configured to point towards the second firewall (for vpn connectivity).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 01 Jul 2010 23:50:41 GMT</pubDate>
    <dc:creator>Jennifer Halim</dc:creator>
    <dc:date>2010-07-01T23:50:41Z</dc:date>
    <item>
      <title>firewall and network segment question</title>
      <link>https://community.cisco.com/t5/network-security/firewall-and-network-segment-question/m-p/1450252#M640522</link>
      <description>&lt;P&gt;hi! based on the diagram i attached. In the internal network can i configure everything to be in the on segment and one vlan? I just want to have a simple setup in the branch office, that enable internet traffic to go through the optical link and corporate resources access to go through the adsl vpn. or if possible internet access to go through the adsl/vpn link as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this case i'm thinking of disabling vlan 1 and configure only one vlan for the entire LAN (flat network).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is that possible with 2 firewalls connection and based on my requirements above?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thx&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:06:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-and-network-segment-question/m-p/1450252#M640522</guid>
      <dc:creator>dlee_gmail</dc:creator>
      <dc:date>2019-03-11T18:06:22Z</dc:date>
    </item>
    <item>
      <title>Re: firewall and network segment question</title>
      <link>https://community.cisco.com/t5/network-security/firewall-and-network-segment-question/m-p/1450253#M640572</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, base on your diagram, it would be best to just have 1 firewall since you do not have a router/L3 switch in your internal network that can do the routing to 2 firewalls.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe your preference would be to route everything towards the VPN/ADSL connection?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you would like to route traffic towards 2 firewalls, ie: one for internet connection and the other for vpn traffic, then you would need to have a router/L3 switch to route the traffic accordingly as follows:&lt;/P&gt;&lt;P&gt;- Traffic towards the internet would have default route/default gateway configured towards the first firewall (for internet connectivity).&lt;/P&gt;&lt;P&gt;- Traffic towards the VPN would have specific routes (remote/HQ LAN subnets) configured to point towards the second firewall (for vpn connectivity).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Jul 2010 23:50:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-and-network-segment-question/m-p/1450253#M640572</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-07-01T23:50:41Z</dc:date>
    </item>
  </channel>
</rss>

