cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
407
Views
0
Helpful
1
Replies

Using one Content Switch across two secure DMZ's

eoin
Level 1
Level 1

I'm currently trying to configure an 11503 to loadbalnce 2 groups of servers that are located in 2 separate DMZ's. Each DMZ has to be completely secure from one another. If I configure Circuit ip address's for each of the 2 VLANS (each VLAN is separated by a firewall). The CSS will automatically setup routing between them. I have looked at the two commands "ip uncond-bridging" and "no ip opportunistic" but feel these will not be sufficient to separate the two VLANS.

1 Reply 1

Gilles Dufour
Cisco Employee
Cisco Employee

why don't you move your CSS to another vlan so the firewall is between the CSS and the servers ?

example

.......CSS

........|

......Firewall

.......|....|

.vlan1-+....+---- Vlan 2

Like this the CSS can do loadbalancing to the different servers but the firewall is still there.

Gilles.

Review Cisco Networking for a $25 gift card