01-28-2003 12:14 AM - edited 03-09-2019 01:52 AM
I liked to find out if there is any other way to configure DMZ on a Cisco 2950. What I normally do is to create a VLAN for DMZ.
01-28-2003 12:58 PM
You could use protected ports also.
Protected ports on the same switch will not be able to communicate with each other. Protected ports can communicate with all other unprotected ports on the switch.
Example would be a colo facility and each customers box would be on a protected port in same VLAN and only one unprotected port in VLAN going to router, etc. This way they can have several customers on the same IP subnet (VLAN) and traffic doesn't go between the ports.
01-28-2003 05:32 PM
do you think you could provide me with a sample configuration for using protected ports?Much appreciated.
01-29-2003 12:31 AM
interface FastEthernet0/1
! This marks the port as a private VLAN edge port.
switchport protected
interface FastEthernet0/2
switchport protected
interface FastEthernet0/3
switchport protected
Protected ports do not forward any traffic to protected ports on the same switch. This means that all traffic passing between protected portsunicast, broadcast, and multicastmust be forwarded through a Layer 3 device.
.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide