02-16-2017 06:07 AM - edited 03-12-2019 01:56 AM
Hi,
I'm not a network engineer myself, but will try and communicate this best I can. Please bear with me.
I have servers on a subnet that I need to segment for security reasons. Currently they are all in a single VLAN. I'd like to complete this segmentation without readdressing. I would like to have a firewall between these segments. Everything is patched into a 4500 switch running in layer 3 mode.
My idea;
I hope that makes sense?
Is what I am proposing possible?
Any advice or suggestions welcomed.
Many thanks
Mark.
02-16-2017 06:13 AM
Each server in own vlan (with /30 mask as a example)
and depending on the version of the ASA software to configure the access rights between them (through access lists or NAT)
02-16-2017 07:33 AM
Thanks for reply FrOg.
So essentially you are saying what I suggest will work? I don't want to segment individual servers, but groups of them.
MD
02-16-2017 01:24 PM
FTDs in ASA with Inline Sets. Acts like a bump on the wire, without having to change anything in your current addressing, only cabling.
Or you could do with ASA OS and Firepower in transparent mode. It's not as "invisible" as the FTD with inline mode, but it could do the trick.
Or you can use other products, like 8000 series, 7000 series, which you can be used inline and can do more hardware level things.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide