Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations biv343 on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Backbone configuration

Status
Not open for further replies.

drewdown

IS-IT--Management
Apr 20, 2006
657
US
This is more of a concept question than anything. I have a demo environment setup and right now its just a physical subnet. Gi1/0/3 on the core layer 3 switch is configured as a physical interface with an IP address of 172.23.16.5 and running OSPF.

Could I create a vlan on the core switch, give it an ip address of 172.23.16.5 and simply make gi1/0/3 a member of that vlan? And be done with it? I ask because I set up the network this way so that 172.23.16.0/24 would be a backbone network, but quickly realized that if I wanted to put devices on that network I would have to seperate them physically, which I don't want to do. Would rather be able to vlan everything.

vlan_or_subnet.gif
 
Why do you want 2 firewalls on the same vlan? Not sure what you wanna do here...but to answer your question, yes.

Burt
 
They would be for redundant internet lines. IE if FW-A goes down then traffic would flow out of FW-B.

Should it be configured another way?
 
HSRP on the Firewalls would be best as long as you are not hosting anything inside your network.

----------------------------------
Bill
 
You probably don't want to do that as having 2 distinct firewalls can bring up security and/or other issues.

You want a firewall that can be in say a cluster or failover type situation. This way the configurations can be synchronzied immediately and not leave potentional vulnerabilities by configuring fw1 one way and fw2 another.
 
I would also think that the firewalls would be on two different vlans...

Burt
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top