Allow routing via Internal firewall for Core switch & Internet firewal

Hi, we have below architecture in which routing between different firewall take place via Internal firewalls only. We have used the core switch only to create VLANs and Connect to access switch. We also have Internet firewall which is connected to core switch. As there is no routing is done in the core switch, how user will access the internet via internal firewall. Please suggest the configuration to be followed. I am not sure whether @MHM Cisco World @Aref Alsouqi @rob_ingram  remember it or not as I asked this question before. Please let me know at Internet firewall side, which port I need to create? It will be Access port or sub interface? Please help me with one quick example.




Hello @inhamit,

All VLAN have got their Gw to the internal FW ?

What about create a vlan between internal and Internet FW ?  Each equipement hold IP ADD on a specific subnet (/30), relayed by this VLAN on CORE Switch.

Then, configure BGP between Internet and Internal Firewall. Internet Firewall would announce default route to Internal Firewall. Internal Firewall would announce the differents subnets. Internet FW would do NAT plus Filtering.

yes All Internal VLAN's have default gateway to Internal firewall.

I have created Internet VLAN  (VLAN 100) in core switch as core switch is placed between Internal and Internet firewall. The VLAN have default gateway in internal firewall ( and Trunk port is configured between core switch and Internal firewall.

Core switch and Internal firewall is connected over Access port  (Access port is configured in core switch and Internet firewall side This access port is linked to VLAN 100). I have also created the Internet VLAN (VLAN 100) in Internet firewall.

Now Do I need to create BGP between Internet and Internal firewall? How can I verify the configuration? Can u please give some commands as an example.


you might be better off looking at this logically than physically.




@ammahend what do u mean by Edge FW here? Core switch is placed between Internal firewall and Internet firewall. Yes, core switch is acting like L2 here.


