06-11-2024 03:40 PM
I need to service Isolated VLANS and I don't want to use VM's or setup a DHCP server for each VLAN. Since I need more than 256 IP's on many VLANS, I'm trying to figure out what to do. I do have 9400 switches connected to the FTD's but I'm wavering between setting the vlans up in VRF's with DHCP on the switch to isolate or PBR or something else. NOT being able to host VLAN's directly on the FW is a major blow and again, can't exactly host them on the FW when I can't have the services attached to the VLAN. What's the best option to create isolated VLANS and then have the FW route to critical services with the FW rules in place.
Solved! Go to Solution.
06-11-2024 09:07 PM
the 9400 with VRF is a decent option ... the only other option is a DHCP server like windows or linux... you can have multiple VRFs and the dhcp server can be in the global .. https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipaddr_dhcp/configuration/xe-3s/dhcp-xe-3s-book/dhcp-relay-agent-xe.html
06-11-2024 09:07 PM
the 9400 with VRF is a decent option ... the only other option is a DHCP server like windows or linux... you can have multiple VRFs and the dhcp server can be in the global .. https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipaddr_dhcp/configuration/xe-3s/dhcp-xe-3s-book/dhcp-relay-agent-xe.html
06-12-2024 08:50 AM
Thank you. This is the solution!! works like a charm!
06-12-2024 02:35 AM
Sorry I dont get your requirement
can you more elaborate
MHM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide