Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

security question

Is it a security issue or concern to add the Internet router on the same DMZ switch but on a different VLAN. To make the question clear here is the setup.

The Internet router in on the outside interface of an ASA firewall and the DMZ switch is on the DMZ interface of the Firewall with a security level of 50.

Sent from Cisco Technical Support iPad App

1 ACCEPTED SOLUTION

Accepted Solutions
Red

security question

Hi H,

There are no security concerns if you plug the DMZ interface and the Internet Router on  the same switch until they are separated in differet vlans with correct cofiguration.

Thanks,

Varun

Thanks, Varun Rao Security Team, Cisco TAC
5 REPLIES
New Member

security question

Can anyone help out please?

Regards,

H

Red

security question

Hi H,

There are no security concerns if you plug the DMZ interface and the Internet Router on  the same switch until they are separated in differet vlans with correct cofiguration.

Thanks,

Varun

Thanks, Varun Rao Security Team, Cisco TAC
New Member

security question

What about the L2 attacks ( VLAN hopping for example? )

Red

security question

Hi H,

For that your configurations needs to be strict, no traffic should be allowed over native vlans, instead they should be specified in access vlans. Do not set the trunks to auto negotiate. Such steps can be taken to mitigate such L2 attacks and gain access to your DMZ resources without passing through the ASA.

Thanks,

Varun

Thanks, Varun Rao Security Team, Cisco TAC
New Member

security question

To answer it in simple there is no security concern with the Internet router on the DMZ switch but you need take care of all the L2 Layer type of attack by hardening the Switch configuration.

240
Views
5
Helpful
5
Replies