2 VLAN on same switch to a firewall
dppagc
Member Posts: 293
I don't understand why a switch needs 2 VLAN to the same firewall.
Device outside (VLAN X) === Firewall ==== Device inside (VLAN Y)
In my case, the inside device has vlan X and Y configured on it. Why?
Device outside (VLAN X) === Firewall ==== Device inside (VLAN Y)
In my case, the inside device has vlan X and Y configured on it. Why?
Comments
-
Iristheangel Mod Posts: 4,133 ModCheck out some of the entries on VLANs and firewalls here:
http://tinyurl.com/zz8bfzf -
OctalDump Member Posts: 1,722I'm not sure I understand the question. It seems like you are asking why one side of the firewall needs to be segregated from the other side of the firewall.
Is the inside device with VLAN X+Y a switch? Because if that's the case, then logically, you could think of them as two separate switches. The only way for data to flow between the VLANs is with a layer 3 device. You could, in theory, set up an end point (eg a server) connected to a trunk to the switch and have access to the two VLANs on two different 'virtual' interfaces.2017 Goals - Something Cisco, Something Linux, Agile PM -
dppagc Member Posts: 293I see. In that case may I ask if a firewall is a purely layer 2 device or does it have layer 3 properties as well? (like an L3 switch)
-
OctalDump Member Posts: 1,722I see. In that case may I ask if a firewall is a purely layer 2 device or does it have layer 3 properties as well? (like an L3 switch)
Usually firewalls operate at layer 3 - connecting to various subnets -, however there are layer 2 firewalls which are also called transparent or bridging firewalls. Some firewalls can be configured to work in either mode.2017 Goals - Something Cisco, Something Linux, Agile PM -
dppagc Member Posts: 293Are there firewalls that accept routing protocols? In my network, it seems that only static routes are accepted.
-
jamthat Member Posts: 304 ■■■□□□□□□□Are there firewalls that accept routing protocols? In my network, it seems that only static routes are accepted.
Yes, typically firewalls will also support dynamic routing protocols