It has been recommended to me to converge my internal network and public Internet into a single 6509 switch with FWSM. I was told to do it with VLANS and that it would have line speed performance. How can this be done?
You can do this but you need to be careful. If you have the internet facing DMZ and your internal network on the same switch chassis then a misconfiguration can easily lead to your internal network being exposed to the Internet.
Do you need line speed performance from the Internet ?. It's unlikely that you have that fast a connection.
If you do decide to do it you must make sure that your MSFC routed interfaces are all behind the FWSM. The vlan you create for the internet DMZ must have it's default gateway set to the FWSM. You must not create a layer 3 interface on the MSFC for your internet DMZ.
You also need to be aware that vlans do not give the same level of security as separate dedicated switches. It comes down to how much security you require, ie. what are you trying to protect and who would like to get to it.
Attached is a link to Cisco whitepaper on vlan security
Question We run asr9001 with XR 6.1.3, and we have a very long delay to
login w/ SSH 1 or 2 to the device compare to IOS device. After
investigation, the there is 1s delay between the client KEXDH_INIT and
the server (XR) KEXDH_REPLY. After debug ssh serv...
Introduction The purpose of this document is to demonstrate the Open
Shortest Path First (OSPF) behavior when the V-bit (Virtual-link bit) is
present in a non-backbone area. The V-bit is signaled in Type-1 LSA only
if the router is the endpoint of one or ...
Hi, I am seeing quite a few issues with patch install and wanted to
share my experience and workaround to this. Login to admin via CLI, then
access root with the “shell” command Issue “df –h” and you’ll probably
see the following directory full or nearly ...