12-03-2010 06:39 AM - edited 03-09-2019 11:18 PM
Hi All,
What is the best practice to segment off the servers vlan.
There have been some discussions where we have been suggested to.... may be put a firewall in the front of core switches and have all traffic go through that.
How realistic is this given the numbers around 200 including AD, exchange, SQL.....VM's.
We already have seprate VLAN's.
12-06-2010 07:49 AM
anyone
any suggestions?
12-08-2010 09:07 PM
From a security standpoint it is recommended to put them behind a firewall on a DMZ interface away from the rest of the network, this is to control inbound and outbound access. With that being said, you need to consider if any of the services you provide on those servers is sensitive to NAT translations, if there is no problem with NAT you can have the firewalll translate.
Javier Zamora
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide