cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
270
Views
0
Helpful
1
Replies

firewall and network segment question

dlee_gmail
Level 1
Level 1

hi! based on the diagram i attached. In the internal network can i configure everything to be in the on segment and one vlan? I just want to have a simple setup in the branch office, that enable internet traffic to go through the optical link and corporate resources access to go through the adsl vpn. or if possible internet access to go through the adsl/vpn link as well.

In this case i'm thinking of disabling vlan 1 and configure only one vlan for the entire LAN (flat network).

Is that possible with 2 firewalls connection and based on my requirements above?

thx

1 Reply 1

Jennifer Halim
Cisco Employee
Cisco Employee

OK, base on your diagram, it would be best to just have 1 firewall since you do not have a router/L3 switch in your internal network that can do the routing to 2 firewalls.

I believe your preference would be to route everything towards the VPN/ADSL connection?

If you would like to route traffic towards 2 firewalls, ie: one for internet connection and the other for vpn traffic, then you would need to have a router/L3 switch to route the traffic accordingly as follows:

- Traffic towards the internet would have default route/default gateway configured towards the first firewall (for internet connectivity).

- Traffic towards the VPN would have specific routes (remote/HQ LAN subnets) configured to point towards the second firewall (for vpn connectivity).

Hope that helps.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card