My network covers central and several branch offices. All connections to regional offices and internet is through MPLS. Thus some of the private addresses comunication are passed through isp router and together with comunication to internet it goes to peer router at their premises, and backwards.
The company has several servers to put in the DMZ zone. I have to administer my own central router - firewall, which is used for VPN communication and some routing functions. My VLANS in the central location are 192.168.20.X - 192.168.40.X).
What I need is the way to separate private from public communication straight after the ISP router. That ashould be done on my switch 3560.
Therefore It needs to separate private traffic 192.168.x.x( regional offices 192.168.100.x - 192.168.109.x - they are not in VLAN structure) from the traffic to and from internet.
Do I need to inlude some form of routed ports and on the top of that some input access lists( to put them in differnet direction). It sound complicated and believe that it might have some simler way to do that.
My cisco switch L3 3560 with standard instruction set Cisco IOS Software, C3560 Software (C3560-IPBASE-M), Version 12.2(35)SE5, RELEASE SOFTWARE (fc1).
So, that "mix" communication is what I have at the input point of their router. I do not have ip vrf command or such under my control. The idea was that Catalyst could separate private and internet communications for input and for output. Bear in mind that I have ensure that input and output part have to the the same.
I do know that I can put vlans and even vlan for DMZ. But I want to see whether the routing functionality of Catalyst 3560 could do the job.
Can I do it with Catalystonly or maybe some additional device such as Mikrotik router will do the job?
Just to add thatCatalyst's command set is standard.
Hi everyone, I would like to thank you in advance for any help you can provide a newcomer like myself!
Im studying the 100-105 book by Odom and am currently on the topic of Port security. I purchased a used 2960 and I'm trying to follow a...
While deploying a number of 18xx/2802/3802 model access points (APs), which run AP-COS as their operating platform. It can be observed on some occasions that while many of their access points were able to join the fabric WLC withou...
I am going to design and build an LAN network under a tunnel underground with long distance between the switches.
I will have 2 Catalyst switches and 8 Industrial IE3000, and they will be connected with fiber.
For now I am planning on use Layer-2 s...