08-30-2008 04:42 AM - edited 03-06-2019 01:05 AM
Scenario:
Internet Client request hits the FWSM and then gets routed to ACE module for load balancing.
VLANs defined on FWSM are 5 (outside), 6 (DMZ), 7 (inside). Client requests are forwarded to DMZ segment where server farm is located.
My question is whether the client VLAN on the ACE module should be the same as DMZ VLAN on FWSM i.e. VLAN 6.
Rgds.
Solved! Go to Solution.
08-30-2008 05:26 AM
in this case correct
because in this case the path will baypass the FWSM
good luck
if helpful rate
08-30-2008 04:59 AM
ofcourse it must be
if not how they gonna comunicate
they should be on the same vlan and the same ip subnet
imagnate exactly like to directly connected interface!!
but dont make SVI for this VLAN on the MSFC
if helpful Rate
08-30-2008 05:24 AM
So for the SVI, it would have been defined if the client VLANs were not going through FWSM, but would have hopped across different VLANs via the MSFC. Is it correct ?
08-30-2008 05:26 AM
in this case correct
because in this case the path will baypass the FWSM
good luck
if helpful rate
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide