12-29-2023 06:09 AM - last edited on 12-29-2023 07:18 AM by rupeshah
I am looking for best practices regarding implementing a firepower-2110 only to protect my internal vlans. I have 10 vlans that I want to protects from the other 20 vlans. The firewpower will typically not have outside/Internet access. Is it better to use subinterfaces, vni interfaces or something else?
Thank you,
Solved! Go to Solution.
12-29-2023 06:22 AM
I prefer to use subinterfaces and sometimes VRF's on the LAN where is needed, now if you need to follow compliance (e.g PCI, etc) you might need to evaluate the need for physical segregation instead. Performance over Security is something that need to be weighted
There are a couple of Design considerations that you need to take into account, but only you can decide
12-29-2023 06:24 AM
config two zone, and traffic not pass between zone in FTD.
this make each VLAN groups can not connect to each other.
it not matter if you config subinterface or VLAN
MHM
12-29-2023 06:22 AM
I prefer to use subinterfaces and sometimes VRF's on the LAN where is needed, now if you need to follow compliance (e.g PCI, etc) you might need to evaluate the need for physical segregation instead. Performance over Security is something that need to be weighted
There are a couple of Design considerations that you need to take into account, but only you can decide
12-31-2023 02:56 AM
Thank you Ruben.
This information as helped me determine how I am going to configure my ASA network.
12-29-2023 06:24 AM
config two zone, and traffic not pass between zone in FTD.
this make each VLAN groups can not connect to each other.
it not matter if you config subinterface or VLAN
MHM
12-31-2023 02:56 AM
Thank you MHM,
Thank you Ruben.
This information has helped me determine how I am going to configure my ASA network.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide