cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
702
Views
0
Helpful
2
Replies

Firewall: Multiple interfaces in diferent VLAN vs multiple redundant with VLAN tagging

Hi all!

I'd like to know de pros and cons of these two aproaches for setting interfaces in an  ASA:

Premises:

There are four different VLAN that must be connected to firewall.

Firewall has 4 physical Interfaces (as default in 5510)

option 1)

               Define 4 interfaces each one in each VLAN.

option 2)
               Define 4 Vlan interfaces using 802.1q encapsulation on a physical interface and use other  interface as redundant.

** Bandwith in the trunked port is not critical here.

Thanks

2 Replies 2

Hi,

   I'd go for option(2) because you can use redundant interface features on ASA and also redundant VLANs because of trunk ports.  Actually If I can go for option3 , I will.

Option 3) , Upgrade OS 8.4 (Check Hardware first) on ASA and use "Etherchannel Features" on trunk ports.

HTH,

Toshi

Florin Barhala
Level 6
Level 6

It's a matter of redundancy and available ports. If you require 1st one, you will use one port for each vlan; if you will expand later your network it is more scalable to have those Vlans bundled under one port.

I would stick to a middle solution: one interface for Internet, one interface for Lan, one interface for DMZ, one interface bundled with the rest of existing VLANs.

Review Cisco Networking for a $25 gift card