cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2353
Views
0
Helpful
1
Comments
alessandro311
Community Member

Dear all,

I am a new comer to networking, my company's situation is similar to the following:

http://www.tak-chung.com/projects/project_student/2006-2007/na06a1/image.jpg

My question is:

1. how to restrict access between servers within the server farm?? e.g. in the community VLAN, I would like to block the access from DC01 to the database server.

2. If I set up a server running tripwire tool, how can I restrict each login to server within the server farm must first pass through the tripwire server, including access from an IP within the same community VLAN??

Thank and appreciate for any comments!!!

Comments
Collin Clark
VIP Alumni
VIP Alumni

You'll have to use PVLANS

http://www.cisco.com/en/US/tech/tk389/tk814/tk840/tsd_technology_support_sub-protocol_home.html

If you're open to design considerations I would look at creating multiple vlans, separating each by business function or security level. I would use a firewall to restrict access between the different subnets. That way you can filter ports and protocols between systems.

Hope it helps.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: