- Community Home
- >
- Networking
- >
- Switching and Routing
- >
- Aruba & ProVision-based
- >
- vlan for firewall
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-06-2012 02:05 PM
тАО12-06-2012 02:05 PM
vlan for firewall
- Tags:
- firewall
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-06-2012 03:56 PM
тАО12-06-2012 03:56 PM
Re: vlan for firewall
All that depends on your environment and how your firewall & switches are configured. If you haven't configured ACLs in your core switch, then putting your firewall in a separate VLAN will accomplish nothing.
This is really a question about network toplogy design, and for that you should consult someone experienced in network design, and have your requirements/concerns ready as an input to the design process; a security risk assessment would be an important part of this process as well.
Paul
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-07-2012 01:54 AM
тАО12-07-2012 01:54 AM
Re: vlan for firewall
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-07-2012 02:10 PM
тАО12-07-2012 02:10 PM
Re: vlan for firewall
Hi Brad,
Let me try to ask a few more questions to explain it: what would you achieve by putting your firewall in a separate VLAN? Protecting your firewall from your PCs? Protecting your PCs/servers from a potentially compromised firewall? Improved performance? In all of these scenarios, if your switch just routes packets directly between your PCs/servers and your firewall, it adds nothing to your solution.
To back up a bit and answer your original question: yes, it's common practice to put your Internet connection in a separate VLAN, if you've got an internal firewall (or switch ACL) that is routing between your internal network and your external connection. If not, it doesn't seem to me that it adds much value.
I hope that makes sense.
Paul
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-07-2012 05:44 PM
тАО12-07-2012 05:44 PM
Re: vlan for firewall
that is the reasoning behind my post. I'm not sure if that design (if it happens to be incorrect of course) changes your suggestions and comments above?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-08-2012 03:04 AM
тАО12-08-2012 03:04 AM
Re: vlan for firewall
Paul
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-08-2012 04:08 AM
тАО12-08-2012 04:08 AM
Re: vlan for firewall
this may be difficult for you to answer without knowing my corporations network but does it sound correct to put the firewall into the same vlan as servers?
I may be repeating myself so I guess I'm just wondering what other people would do in this situation?
would people only put the firewall into a different vlan if there were an internal router etc as you mentioned earlier?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-08-2012 01:35 PM
тАО12-08-2012 01:35 PM
Re: vlan for firewall
When it comes to network design, there aren't a lot of wrong answers. Putting the servers & firewall in the same VLAN might be fine, or it might be a bad idea - it depends on a lot of other factors.
If you want to see what other people have done, google for some network diagrams - there are whole sites dedicated to it.
Paul