Internet connection routed port or VLAN

Unanswered Question
May 30th, 2008

just an open question regarding the best way to set up the external internet connection on a LAN.

on our core switch we have a user subnet on vlan10. the default gateway of which is the vlan interface on

the internal address of our firewall is on (this is the default gateway of the switch) and is also going to be connected in to the switch.

would it be preferable to set up an "internet" vlan and connect the firewall in to this; or to use a routed port on say

any opinions are welcome...

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Jon Marshall Fri, 05/30/2008 - 02:31


As long as the connection between your firewall and your switch is dedicated ie. no client/servers assigned then it really doesn't matter too much.

With firewalls we usually use vlans but that is because we have failover pairs and they need L2 adjacency. So if you think you will be looking to have a failover pair in future i would go with a vlan.



This Discussion