DMZ - Layer 2 or Layer 3 switch?

Unanswered Question
Jun 11th, 2008

I have a pair of ASAs. I want to create a DMZ with a gigabit there any reason to use a layer 3 switch over a layer 2 switch? All the routing from internal/external to DMZ will be handled by the ASA...

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Jon Marshall Wed, 06/11/2008 - 08:40

No good reason to use a L3 switch, in fact it is more secure to only use a L2 switch and have routing off the ASA which is what you propose.

If you only had a spare 3560/3750 you could just turn ip routing off ie.

switch(config)# no ip routing



This Discussion