07-29-2012 08:48 PM - edited 03-03-2019 06:42 AM
I have a question on the build new Data Center - The requirement is have Vlan segmentation from Prod/App/DB and users - There is a suggestion from the team to used Firewall as routing and gateway where the Core switch remain unfunction at all. Total host for this new DC is around 200 server (Clas C/24) -
Question
1. Does firewall allowed to do routing for enterprise network
2. Does any enterprise firewall can do routing to cater class c /24 subnet
07-29-2012 09:07 PM
08-03-2012 05:09 AM
It's depending on how you could like to setup your network.
I probably would suggest to put all your internal network behind a/pair of firewalls with different zones to ensure the layer 2 and layer 3 seperation and security. And using your core switch to do the non-firewall routing if you core switch is 4500 or 6500.
08-04-2012 01:56 AM
Hi Joe,
the answer is depend on you deisgn
are you isolating these groups in L2 VLANS and using first L3 gateway as a firewall to control the routing between them
or you might consider using VRFs and routig isolation with firewalls in between as well as described in the below link:
http://www.cisco.com/en/US/docs/solutions/Enterprise/Network_Virtualization/ServEdge.html
hope this help
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide