cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
937
Views
0
Helpful
3
Replies

implementing private VLANs on Firepower

PiotrB
Level 1
Level 1

My department is looking for implementing private VLANs on Firepower 2000 and 4000 series.

Is this feature available or supported on FTD/FMC?

Thanks in advance for the reply.

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

Adding to what @Rob Ingram correctly noted, even the firewall models that support onboard switching (like the Cisco Secure Firewall 1010) do not support private VLANs.

PVLAN is mostly a technology that has been abandoned in favor of other segmentation or microsegmentation techniques. I have seen them in use in production once in over 30 years of experience working with hundreds of customer networks.

View solution in original post

3 Replies 3

@PiotrB Private VLANs are a function of switches, not the firewalls.

https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-3/configuration_guide/vlan/b_173_vlan_9300_cg/configuring_private_vlans.html

 

You can segment networks (VLANs) behind the Firewall, but filtering traffic within the VLAN would not be routed via the Firewall.

Marvin Rhoads
Hall of Fame
Hall of Fame

Adding to what @Rob Ingram correctly noted, even the firewall models that support onboard switching (like the Cisco Secure Firewall 1010) do not support private VLANs.

PVLAN is mostly a technology that has been abandoned in favor of other segmentation or microsegmentation techniques. I have seen them in use in production once in over 30 years of experience working with hundreds of customer networks.

Marvin,

Can you go into a little more detail on the "segmentation or microsegmentation techniques" ?

 

VR

Review Cisco Networking for a $25 gift card