fieryhail
IS-IT--Management
- Mar 12, 2010
- 92
I'm not sure if this is the right area for this or not, f not, I apologize. I've got a PIX 525 with UR license and multiple interfaces (6). Currently I have 2 catalyst switches behind it, one is a 3524XL and the other a 3550-48. I would like to consolidate switches and retire the 3524, putting those hosts in another vlan on the 3550. I would also like to enable intervlan routing on he 3550 since the 3524 currently is connected as a workstation switch. I'd like to have traffic from the workstations to a vlan on the 3550 go all through the 3550 instead of passing through the PIX as it slows down large transfers. Is there a way to have intervlan routing on the 3550 "behind" the PIX? Sorry for being so confusing. For example the current config is:
PIX: xx.xx.xx.xx --> e0 (outside)
3524: 192.168.1.0/24 --> PIX e1 (inside)
3550: 192.168.2.0/24 --> PIX e2 (DMZ1)
3550: 192.168.3.0/24 --> PIX e3 (DMZ2)
With this config any traffic to/from 192.168.10.0 and 192.168.2.0 has to go through PIX. This gets very slow at times with large transfers (1GB+) What I would like is to put the 192.168.1.0/24 on another vlan on the 3550 and have traffic going to/from 1.0 and 2.0 move only through the 3550, using the PIX just for edge. Thanks in advance for any suggestions.
PIX: xx.xx.xx.xx --> e0 (outside)
3524: 192.168.1.0/24 --> PIX e1 (inside)
3550: 192.168.2.0/24 --> PIX e2 (DMZ1)
3550: 192.168.3.0/24 --> PIX e3 (DMZ2)
With this config any traffic to/from 192.168.10.0 and 192.168.2.0 has to go through PIX. This gets very slow at times with large transfers (1GB+) What I would like is to put the 192.168.1.0/24 on another vlan on the 3550 and have traffic going to/from 1.0 and 2.0 move only through the 3550, using the PIX just for edge. Thanks in advance for any suggestions.