Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Community Member

DMZ - Layer 2 or Layer 3 switch?

I have a pair of ASAs. I want to create a DMZ with a gigabit switch...is there any reason to use a layer 3 switch over a layer 2 switch? All the routing from internal/external to DMZ will be handled by the ASA...

1 REPLY
Hall of Fame Super Blue

Re: DMZ - Layer 2 or Layer 3 switch?

No good reason to use a L3 switch, in fact it is more secure to only use a L2 switch and have routing off the ASA which is what you propose.

If you only had a spare 3560/3750 you could just turn ip routing off ie.

switch(config)# no ip routing

Jon

761
Views
0
Helpful
1
Replies
CreatePlease to create content