Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Firewall network design - Need advice

Hi Sir,

Please refer to attached network diagram.

Logically and functionally, there are two networks: Network 1 and Network 2. Core switches of both networks are co-located at each 3 core data centers. Both networks run EIGRP in the same AS 100.

There's a requirement to demarcate these two networks using firewalls, to make Network 2 secure.

The easiest solution is to implement the firewalls in transparent mode, therefore maintaining the EIGRP neighbor adjacencies between the core switches.

If I were to implement routed mode, one main concern I foresee is asymmetric routing across the firewalls. I know FWSM 3.1 has support for asymmetric routing but FWSM is not an option here, mainly because some core switches currently do not have Sup720 or Sup32.

Please advise how the new network could be designed/implemented.

Thank you.

B.Rgds,

Lim TS

  • Firewalling
1 REPLY
New Member

Re: Firewall network design - Need advice

You can safely implement the firewalls here provided yo u are able to break up the advertisments from the N/w 1 -> <-N/w 2

105
Views
0
Helpful
1
Replies
This widget could not be displayed.