10-16-2012 02:50 PM - edited 03-11-2019 05:10 PM
Hi
My basic query is whether a dot1q trunk carrying 2 VLANs (guest wireless and corporate LAN) can still be firewalled using the zone based firewall on an IOS firewall on a 1941 ISR.
Here's more background:
It's for a number of branch sites that will have the ISR as the site WAN router and perimeter firewall, corporate access will go via the WAN MPLS HWIC and internet access will go via an ADSL interface. The concern is the LAN side. Whilst the 1941 has 2 onboard LAN interfaces, the guest wireless is combined with corporate wireless so LAN access will need to be via a trunk link and so ultimately the two VLANs need to be separated via firewall rules.
I know that this wouldn't be an issue on the ASA but I'm not sure whether the zone based firewall on the router would be the same.
Does anyone know whether what I'm trying to acheive is possible on the ISR? I'll try and knock up a diagram and upload if that helps.
Thanks, Anish
Solved! Go to Solution.
10-16-2012 09:02 PM
Hello Anish,
It will not present any issue at all.
Remember that you split the router into zones, so even if you have more than one subnet or vlan behind an interface you can still apply the right security policies to the zone with no issues at all.
Any other question..Sure..Just remember to rate all of my answers.
Julio
10-16-2012 09:02 PM
Hello Anish,
It will not present any issue at all.
Remember that you split the router into zones, so even if you have more than one subnet or vlan behind an interface you can still apply the right security policies to the zone with no issues at all.
Any other question..Sure..Just remember to rate all of my answers.
Julio
10-17-2012 02:16 PM
Super thanks Julio. It may be a while before I can test it out but thanks for your speedy response to the question.
Best, Anish
10-17-2012 02:20 PM
Hello Anish,
My pleasure to help,
Let us know the result
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide