08-02-2011 11:20 PM
Hi All
Hoping someone has had some experience in this area and can answer my questions.
We are about to implement 2 FWSM's into a VSS environment.
Our customer also has VMWare Infrastructure onsite as well, and hosted on that infrastructure will be devices on the "Trusted" and "Untrusted" networks.
On the VMWare environment, vSwitch1 is configured with 4 Nic's in a single etherhcannel which is configured to trunk for all of the VLAN's, Including the Trusted network.
My questions are
Will the Trusted and Untrusted networks still be able to communicate via the FWSM ie
Untrusted Server > MSFC > FWSM > Trusted Server
I m pretty sure I already know the answer to this question, but here goes
Should the Customer Create 2nd VSwitch for the Trusted Servers, and keep the existing VSwitch for the Untrusted Servers
Thanks in advance for any help
08-03-2011 05:09 AM
We have a customer that has this same setup. No need to have a separate vSwitch, you can break out the different VLANs in Port Groups on vSwitch1. VMs are then placed in their respective port groups based on what VLAN they need to be in.
08-03-2011 10:09 AM
Not sure about your requirement in detail vis-a-vis virtual infrastructure but if you also have a need to protect/control inter-VM communication then you can look at Cisco Virtual Security Gateway - firewall for virtual environment. http://www.cisco.com/go/vsg
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide