cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
624
Views
10
Helpful
3
Replies

vrf-lite with firewall issue

ita_hsieh
Level 1
Level 1

hi Guys:

We are about to implement vrf-lite on our 6509 switch. Currently 6509 switch connect to several branches via atm oc3 link. We want to separate each brach office traffic with vrf-lite function. Additionaly each branch office will be subject to different firewall policy. We thought about attach an external firewall to 6509 with dot1q encapsulation. Is this solution working? Appreciate any help.Thanks.

3 Replies 3

jbrunner007
Level 1
Level 1

why not use a firewall service module in the 6500? its a high performance firewall and providing you purchase the correct number of context license for the number of virtual firewalls (offices?) you intend to have it will work nicely. You can create a separate virtual firewall for each office. The virtual firewall is a pix with in a pix. There is one admin context used to define the vlans associated with each firewall instance.

On each vlan layer 3 interface "behind" the firewall you can define the vrf. I think this will allow you to avoid an external firewall and provide top-notch security.

Joe

Yes, it will work using a external firewall or for that matter an internal FWSM.

As in both cases, the FW is not VRF aware, and the interfaces are treated as any other inside/outside interface.

HTH-Cheers,

Swaroop

hi is it ok that I only have a multi-vrf CE without PE and P router in this case?Thanks for help.

regards

Alex