02-06-2007 08:41 PM - edited 03-03-2019 03:39 PM
It has been recommended to me to converge my internal network and public Internet into a single 6509 switch with FWSM. I was told to do it with VLANS and that it would have line speed performance. How can this be done?
02-06-2007 10:47 PM
Hi!
Good day! Depends on your resources but this link may be helpful.
Hope this helps! ?
Regards,
Albert
02-07-2007 12:02 AM
Hi
You can do this but you need to be careful. If you have the internet facing DMZ and your internal network on the same switch chassis then a misconfiguration can easily lead to your internal network being exposed to the Internet.
Do you need line speed performance from the Internet ?. It's unlikely that you have that fast a connection.
If you do decide to do it you must make sure that your MSFC routed interfaces are all behind the FWSM. The vlan you create for the internet DMZ must have it's default gateway set to the FWSM. You must not create a layer 3 interface on the MSFC for your internet DMZ.
You also need to be aware that vlans do not give the same level of security as separate dedicated switches. It comes down to how much security you require, ie. what are you trying to protect and who would like to get to it.
Attached is a link to Cisco whitepaper on vlan security
http://www.cisco.com/en/US/products/hw/switches/ps708/products_white_paper09186a008013159f.shtml
HTH
Jon
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide