cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
500
Views
0
Helpful
2
Replies

Shared Firewall config

pcattell
Level 1
Level 1

Requirement: Multiple small vlans behind a single shared firewall.

Current proposed setup: Pix or Nokia FW-1 firewall connected on the outside interface to Internet Backbone providers, inside Lan interface connected to 2948 switch to provide multiple vlan's to groups of web servers. It is esential that the hosts on the vlan's are not able to see any other host on another vlan. The firewall is running NAT.

Problem: It is not possible to setup truncking between the 2948 and firewall (required to enable the correct use of vlan's.

Possible solution(?): A 2621 router is placed between the firewall and switch to enable the switch to use truncking. Problems with NAT and ARP between the firewall and vlan hosts.

Is there anyone who has managed a similar setup?

2 Replies 2

g.rodegari
Level 1
Level 1

Pix only support Ethernet II (DIX) encapsulation.

No trunking protocol are supported.

Graz.

s-ariga
Level 1
Level 1

HI

You can use a pix firewall(525 or 535) with more than 2 interfaces .The number of ethernet interfaces should be equal to the number of vlans (theres a limit though to the number of ethernet cards a pix 515,525,535 can support)and and routes ,nats ,static and global commands in the firewall.

Hope the above thing makes some sense??