04-09-2018 01:29 AM - edited 02-21-2020 07:36 AM
Hi Guys,
I have two ISR and two FTD firewalls connected directly with each other with redundant links (triangle shape). My question here do I need to put a L2 sw between FTD and ISR instead of directly connection? Is it healthy to do this? Or not needed?
Thanks for all
MK saeed
04-09-2018 02:38 AM
04-09-2018 02:53 AM
So it's for future expansion reason? but I thunk if I put switch will be a security weakness point?
04-09-2018 03:14 AM
theoretically yes. you could choose to manage it using and IP address in a VLAN that you stretch into your DMZ. alternatively is you want to be more secure. dont stick an IP address on it at all and manage the switch through console.
04-09-2018 04:19 AM
So it's better like this: ?
ISP----ISR---L2 SW---ASA FTD---Core SW
and L2 sw will harden it with ACL ans SSH to make much secure!
04-09-2018 04:04 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide