cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
280
Views
0
Helpful
2
Replies

Query

ray_stone
Level 1
Level 1

Hi,If i create V-lans on FW and same V-lans I configure on switch. Which one wud be great option as per security concerned. Switch or FW???? Thanks.

1 Accepted Solution

Accepted Solutions

abinjola
Cisco Employee
Cisco Employee

Its better to have VLANs configured on FW

a)FW treats VLAN on itself just like another logical interface

b)Will not allow traffic to flow across this VLAN/Interface unless you have ACLs and translation in place, also only traffic for which there is a valid connection would be allowed to this VLAN

c)Switch does not have statefull nature/security , which means if there is Inter-VLAN routing enabled on this switch the packet would start flowing to/from this "VLAN"

unless you have VACLs blocking this traffic,which again is only L3 security but no statefullness

View solution in original post

2 Replies 2

abinjola
Cisco Employee
Cisco Employee

Its better to have VLANs configured on FW

a)FW treats VLAN on itself just like another logical interface

b)Will not allow traffic to flow across this VLAN/Interface unless you have ACLs and translation in place, also only traffic for which there is a valid connection would be allowed to this VLAN

c)Switch does not have statefull nature/security , which means if there is Inter-VLAN routing enabled on this switch the packet would start flowing to/from this "VLAN"

unless you have VACLs blocking this traffic,which again is only L3 security but no statefullness

Thanks!!

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: