It is a design related query. Please find the attached Diagram.
I have 2 firewall & 2 Routers & 2 Switches to be operated in redundancy.
My customer is asking connected the cables and configure the setup as shown in the diagram marked with yellow colour. Now to achieve this I have used a Layer 2 switch to connect the cables between Firewall and Router and another Layer 2 switch to connect the cables between the firewall and Switches.
Is this is a best practice and only option to connect the Devices in this fashion (as shown as Yellow colour in the Diagram attached). Wont it bring the latency or Single point of failure??
I think a better way would to be use the (2) layer 2 switches as a redundant pair and create two vlans; one for firewall to router and another for firewall to switches. This will eliminate a single point of failure and still provde enough switching for both areas.
1..I also agree with Colin but VLAN should be non-routable (no ip address to configure VLAN interfaces of the switch.
2. You may free to user the existing switch you your security policy advise for Layer-3 seperation
3. If your policy states that internal network and external network should have Layer-1,2,3 seperation then you have to deploy additional switches between router and firewall. (this is best practice as well)
Best practice depends on your organization security policies...
Hi everyone, I would like to thank you in advance for any help you can provide a newcomer like myself!
Im studying the 100-105 book by Odom and am currently on the topic of Port security. I purchased a used 2960 and I'm trying to follow a...
While deploying a number of 18xx/2802/3802 model access points (APs), which run AP-COS as their operating platform. It can be observed on some occasions that while many of their access points were able to join the fabric WLC withou...
I am going to design and build an LAN network under a tunnel underground with long distance between the switches.
I will have 2 Catalyst switches and 8 Industrial IE3000, and they will be connected with fiber.
For now I am planning on use Layer-2 s...