12-29-2009 08:32 AM - edited 03-04-2019 07:04 AM
Hello
1)what is the benifits of using switch for the inside and switch for the outside and switch for the DMZ?
2)is it possible to put all the connection for inside,outside,DMZ on the 4507R instead of dedicate switch for each segment?
please clarify
thanks
12-29-2009 08:38 AM
Hello
1)what is the benifits of using switch for the inside and switch for the outside and switch for the DMZ?
2)is it possible to put all the connection for inside,outside,DMZ on the 4507R instead of dedicate switch for each segment?
please clarify
thanks
Ali
It is possible to have inside,outside and DMZ on a single chassis but i wouldn't recommend it. DMZ and internal on the same switch at a push but not the outside.
The benefits of having dedicated switches is that a misconfiguration on one switch or a security bug on one switch isolates the problem rather than affecting inside,outside and DMZ.
If you are firewalling the data centre for example where the outside is the rest of the company WAN, with DMZs and an inside then it is fine to use a 6500 with FWSM for example and have it all on the same switch but i would feel very uncomfortable doing this with the internet on the outside interface.
Jon
12-29-2009 08:48 AM
thanks jon
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide