cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
654
Views
5
Helpful
2
Replies

Firewall placement in a switched network

bnance
Level 1
Level 1

I am installing a 3650 switch with a fiber gbic. I am also installing a d link 1100 firewall. The issue is where to place the firewall. The fiber comes in and will terminate into the 3560 gbic, the will have to be converted to copper and into the firewall, then back to the 3560 again out to the LAN. Will this cause a problem and what other option is their??

2 Replies 2

paddyxdoyle
Level 6
Level 6

Hi,

What are you trying to firewall off, the network on the other side of the fiber?

As long as your switch is layer 3 you could make sure that the fibre port and the external firewall port are in the same VLAN and address the firewal interface and opposite end of the link with a /30 network.

You can then make the internal firewall port a routed port (no switchport) and create a /30 network range and address both the port and firewall from this range

HTH

PJD

Yes that is exactly what i am trying to do. I think the config you sent will work, the switch is a 3560 so i can use routing.

Thank you