cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

357
Views
0
Helpful
1
Replies
Jason Fraioli
Participant

InterVLAN Firewall Options

Good morning,

I am seeking advice regarding firewall capabilities between internal VLANs.  I currently have a collapsed core architecture with a single core switch (4500 series).  All internal VLAN SVIs reside on the core switch.  I'm using access lists to restrict interVLAN communications, but I am wondering what other options I have.  The only thing I can think of is to move the VLAN SVIs to an ASA.  Is that a recommended approach?  Any other suggestions would be greatly appreciated.

Thanks.

1 REPLY 1
Marvin Rhoads
VIP Community Legend

What security policy are you tring to implement?

I ask becasue we seldom see small-medium networks restricting inter-VLAN traffic. We see it sometimes on larger enterprises (with dedicated firewalls for that purpose) and increasingly in data centers separating VMs or subnets ("east-west" firewalling).

An alternative approach is separate VRF instances if the subnets never talk to one another yet share a single core.

Create
Recognize Your Peers
Content for Community-Ad