Requirement: Multiple small vlans behind a single shared firewall.
Current proposed setup: Pix or Nokia FW-1 firewall connected on the outside interface to Internet Backbone providers, inside Lan interface connected to 2948 switch to provide multiple vlan's to groups of web servers. It is esential that the hosts on the vlan's are not able to see any other host on another vlan. The firewall is running NAT.
Problem: It is not possible to setup truncking between the 2948 and firewall (required to enable the correct use of vlan's.
Possible solution(?): A 2621 router is placed between the firewall and switch to enable the switch to use truncking. Problems with NAT and ARP between the firewall and vlan hosts.
You can use a pix firewall(525 or 535) with more than 2 interfaces .The number of ethernet interfaces should be equal to the number of vlans (theres a limit though to the number of ethernet cards a pix 515,525,535 can support)and and routes ,nats ,static and global commands in the firewall.
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
[toc:faq]Introduction:This document describes details on how NAT-T
works.Background:ESP encrypts all critical information, encapsulating
the entire inner TCP/UDP datagram within an ESP header. ESP is an IP
protocol in the same sense that TCP and UDP are I...