08-04-2021 02:34 PM
Dears
i have a small setup and i have a below question related to design
i have a simple question related to the design we usually keep switches in cross connection between the internal firewall and perimeter firewall if incase of failover between the firewall the traffic should flow for this purpose, instead of buying those middle layer switches if i connect the perimeter firewall to the core switch, does it will easy for attacker to screw the core switch if incase my perimeter firewall is compromise ,
Please advise.
08-04-2021 03:14 PM - edited 08-04-2021 03:18 PM
meaning using specific VLAN for router and FW?
NOTE:-this SW called outside SW
08-04-2021 03:41 PM
Is this design Hosted Service model or Enterprise LAN and DC mode? ( any topology diagram will help to understand better)
In General, if the enterprise DC you need to connect to Core switch for Routing in either case. ( that is the reason you have DMZ between the Internal network and the Internet.
08-05-2021 07:59 PM
As long as you don't expose any control plane or layer 3 services on the interfaces and VLANs on the switch that your perimeter firewall connects to, the exposure to external attacks is extremely small.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide