cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1390
Views
0
Helpful
1
Replies

Stateful firewall on Catalyst 3750

alanchia2000
Level 1
Level 1

I have a core sw 3750 with a few downstream access layer switches.

I am planning to implement ACLs on Catalyst 3750, but have come to realise that reflexive ACLs are not supported on the core sw 3750. The closest I get is the "established" keyword that is meant for TCP packets. My question is whether there is a way to implement stateful firewalls between VLANs without using other non "Cisco-ish" monsters.

1 Reply 1

p.krane
Level 3
Level 3

To the best of my knowledge, it is not possible for Catalyst 3750 switch. It is available in cat 6k with FWSM. In Cat 6k when communication occurs between VLANs X and Y, the FWSM is the only available path between the VLANs, forcing traffic to be statefully inspected.