cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
403
Views
0
Helpful
1
Replies

Firewall network design - Need advice

limtohsoon
Level 1
Level 1

Hi Sir,

Please refer to attached network diagram.

Logically and functionally, there are two networks: Network 1 and Network 2. Core switches of both networks are co-located at each 3 core data centers. Both networks run EIGRP in the same AS 100.

There's a requirement to demarcate these two networks using firewalls, to make Network 2 secure.

The easiest solution is to implement the firewalls in transparent mode, therefore maintaining the EIGRP neighbor adjacencies between the core switches.

If I were to implement routed mode, one main concern I foresee is asymmetric routing across the firewalls. I know FWSM 3.1 has support for asymmetric routing but FWSM is not an option here, mainly because some core switches currently do not have Sup720 or Sup32.

Please advise how the new network could be designed/implemented.

Thank you.

B.Rgds,

Lim TS

1 Reply 1

bstremp
Level 2
Level 2

You can safely implement the firewalls here provided yo u are able to break up the advertisments from the N/w 1 -> <-N/w 2

Review Cisco Networking for a $25 gift card