04-19-2023 11:23 PM
Hi, Can we configure the trunk port on Cisco FPR-2110 to communicate with Cisco 9300 series switches? I want to use Cisco FPR-2110 to allow routing between vlans after trunk port configuration.
Solved! Go to Solution.
04-21-2023 09:06 AM
Hi, I got confused with this point "FW internet must connect to one Core SW not to both since the Core SW not run VSS nor vPC".
you Use FW(internet) HA, so I say perfect
I say FW must connect to one Core according to @Aref Alsouqi topology you can make second review you use one FW and connect it to both Core (which not run any stack), we could not connect one FW to two standalone SW, so I mention if you need to use two link use redundancy (one link active and other passive).
hope this clear to you
07-11-2023 03:30 AM
@MHM Cisco World @Aref Alsouqi @Rob Ingram
Please suggest what port I should configure at Internet firewall side to route the traffic from Internal firewall?
04-21-2023 08:40 AM
If you have two ISP firewalls then I think the above design is valid. A single link (or port channel if you want to increase bandwidth) from each of the ISP firewalls to each core switch will do the job.
04-21-2023 10:54 AM
I think you could get away with those individual connections from a single firewall to multiple switches via grouping the interfaces of the firewall into a single logical interface using the IRB feature in routed mode.
04-23-2023 02:28 AM
Quick Question here, Do we have any other option to allow the routing (between few vlans or IP address it should work and between few it restrict) on the same port between different vlan apart from router on stick option on the firewall side. Means, traffic from core switch enter to firewall on the same port and route back on the same port on different vlan as per the defined route .
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide