02-24-2017 06:18 PM - edited 03-12-2019 01:58 AM
Hello guys,
Currently i have set up DMZ zone for my network. The system is being tested using external GSM Network, the connection and the synchronization are successful. Currently the server is directly connected to the DMZ Port at the Firewall.
Can i move the server into my internal network and connect the server using network switch?
Firewall (5508-X)
Router ( ISR 2912/K9)
Switch ( WS-C3850-48P-S )
I have attached current network topology
Solved! Go to Solution.
02-25-2017 06:38 AM
Can i move the server into my internal network and connect the server using network switch?
of course you can, infact I would recommend it for scaleability. If the switch you will be using is a shared switch with the other VLANs in your network then just create a new VLAN, place two ports in this new VLAN and connect the firewall DMZ interface to one port and the server to the other.
--
Please remember to select a correct answer and rate helpful posts
02-27-2017 10:55 AM
So long as the VLANs are trunked to the access switches this should work. Be careful about putting the default gateway on the core switch. If you have any other IP configured on the core then these will be routed directly to eachother. If you want the subnets to be seperate then set the ASA IP as the default gateway with no IP configured on the core switch for the new VLAN. Or, if your core switch supports it, configure VRFs on the core switch and place the new VLAN in a VRF. If the subnets don't need to be seperated then this is not relevant.
--
Please remember to select a correct answer and rate helpful posts
02-25-2017 06:38 AM
Can i move the server into my internal network and connect the server using network switch?
of course you can, infact I would recommend it for scaleability. If the switch you will be using is a shared switch with the other VLANs in your network then just create a new VLAN, place two ports in this new VLAN and connect the firewall DMZ interface to one port and the server to the other.
--
Please remember to select a correct answer and rate helpful posts
02-26-2017 06:20 PM
Thanks, does this configuration work if i connect the DMZ & Server at different switches? The switches has the assigned VLAN and i have configured gateway at my Core Switch
02-27-2017 10:55 AM
So long as the VLANs are trunked to the access switches this should work. Be careful about putting the default gateway on the core switch. If you have any other IP configured on the core then these will be routed directly to eachother. If you want the subnets to be seperate then set the ASA IP as the default gateway with no IP configured on the core switch for the new VLAN. Or, if your core switch supports it, configure VRFs on the core switch and place the new VLAN in a VRF. If the subnets don't need to be seperated then this is not relevant.
--
Please remember to select a correct answer and rate helpful posts
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide