02-26-2023 11:13 PM
Hello
I have a question regarding VLAN access to servers on a Core switch.
See, we have these hardwares in our organization's network
A Fortigate firewall
I want to put a 3850 switch in the network core
15 2960 switches that have the role of Access.
We do not have a Distribute switch.
I want to have 10 Vlans in the network and since the users are in different places, I cannot use Local Vlan and I have to use End to End. These Vlans are going to be created by the Core switch and the VTP service, and I don't want there to be any communication between the Vlans. That is, I don't want to use IP routing on the Core switch.
But all Vlans must have access to DMZ servers and Local Servers.
One way is to define a hardware interface number for each zone (DMZ and Local Server) on the firewall. This causes the load of traffic on the firewall to be high and the traffic of users to access the internal servers comes and goes back to the firewall. (PLAN A)
The second way is to define two VLANs with the names DMZ and Local server on the Core switch and activate the IP Routing service on the Core switch, which allows users to access other VLANs. (PLAN B)
Thank you
02-27-2023 08:41 AM
can I see topology ??
02-27-2023 09:58 PM
02-28-2023 12:18 PM
Segmentation is always good, so you can control what device to access what resource based on the VLAN or Source IP address.
Your plan is the most standard setup, I only see the difference between A and B is VLAN (or is there something I am missing? ( as per the diagram)
you have 2960 to 3850 Layer 2, 3850 to Forgitware and other Service Layer 3.
02-28-2023 09:42 PM
What is your suggestion ?? A or B???
03-01-2023 04:44 PM
I only see the difference between A and B is VLAN (or is there something I am missing? ( as per the diagram)
02-28-2023 10:46 PM
can i see topology?
02-28-2023 10:51 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide