Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Using one Content Switch across two secure DMZ's

I'm currently trying to configure an 11503 to loadbalnce 2 groups of servers that are located in 2 separate DMZ's. Each DMZ has to be completely secure from one another. If I configure Circuit ip address's for each of the 2 VLANS (each VLAN is separated by a firewall). The CSS will automatically setup routing between them. I have looked at the two commands "ip uncond-bridging" and "no ip opportunistic" but feel these will not be sufficient to separate the two VLANS.

1 REPLY
Cisco Employee

Re: Using one Content Switch across two secure DMZ's

why don't you move your CSS to another vlan so the firewall is between the CSS and the servers ?

example

.......CSS

........|

......Firewall

.......|....|

.vlan1-+....+---- Vlan 2

Like this the CSS can do loadbalancing to the different servers but the firewall is still there.

Gilles.

129
Views
0
Helpful
1
Replies
CreatePlease login to create content