08-09-2013 10:23 AM - edited 03-10-2019 06:01 AM
Trying to work out a way using "Firewall" and "IPS" on a stick type configs.
My diagram: http://i.imgur.com/jJI7UcP.png
Theres a lot of unnecessary information missing but thats pretty much what I'm trying to do.
So in the diagram:
- Red lines are physical links (as in there will be 20 x Gigabit Ethernet connections from a WS-48 to each server or workstation... etc)
- Blue lines are trunks
- and the green line is a single phyiscal link to the router
I'm trying to figure out a way to get both Firewall and IPS inline between each of the VLANs on the core switch, I don't think its possible though without going through either the firewall or the IPS twice.
An example, when a host on Server VLAN connects to a host on the Workstation VLAN, it goes through both the firewall and the IPS. When a host on the workstation VLAN connects to a host on the internetit goes through both firewall and IPS...
Any ideas?
08-09-2013 06:02 PM
You might be able to setup VRF to create a separate place on the swtich for each VLAN. Then just use the ASA to route traffic between each.
08-09-2013 09:57 PM
Then how would I fit the IPS in?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide