cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3858
Views
0
Helpful
2
Replies

Firewall with Fiber Connectivity

avilt
Level 3
Level 3

I have 4 remote fiber links terminated on the main floor. Is is possbile to terminate this links directly on the firewall?

Exampls, 4 floors, each with a L2 switch, single vlan. From each floor, a fibre link is connected to the main floor. On the main floor I would like to terminate these links on a firewall. Is there such a firewall model to implement this setup?

2 Replies 2

ROBERT WATSON
Level 1
Level 1

Any of the Midrange ASA firewalls 5512-55 have an expansion module that will accept up to 6 SFP ports to terminate fiber. 

From the sounds of it you may be better satisfied by a stack of say (2) 3650's where you can run a multichassis Etherchannel to each floor limiting your fault domain to individual device and fiber interconnect and the port channel the stack to a FW instead.  In a 2960 or 3650 aggregation design, you can terminate up to 8 SFP connections in a two switch stack. 

This would give you better capacity and resilience than going for the IO expansion route in the ASA itself. 

Marvin Rhoads
Hall of Fame
Hall of Fame

To add to Robert's good suggestion I would add that your question seems to imply that each floor VLAN default 3 gateway would be on the firewall. This would not be a best practice.

You would typically have a lot of traffic local to the campus that has no need to go via the firewall for any security policy enforcement. Using firewall insterfaces and bandwidth for that sort of thing is usually not a wise investment of recourses.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: