Firewall network design - Need advice

Unanswered Question
Mar 9th, 2007

Hi Sir,

Please refer to attached network diagram.

Logically and functionally, there are two networks: Network 1 and Network 2. Core switches of both networks are co-located at each 3 core data centers. Both networks run EIGRP in the same AS 100.

There's a requirement to demarcate these two networks using firewalls, to make Network 2 secure.

The easiest solution is to implement the firewalls in transparent mode, therefore maintaining the EIGRP neighbor adjacencies between the core switches.

If I were to implement routed mode, one main concern I foresee is asymmetric routing across the firewalls. I know FWSM 3.1 has support for asymmetric routing but FWSM is not an option here, mainly because some core switches currently do not have Sup720 or Sup32.

Please advise how the new network could be designed/implemented.

Thank you.

B.Rgds,

Lim TS

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
bstremp Thu, 03/15/2007 - 15:06

You can safely implement the firewalls here provided yo u are able to break up the advertisments from the N/w 1 -> <-N/w 2

Actions

This Discussion