Our current setup has my perimeter firewall as the router of all of our VLANS. I am assuming it is more efficient to use an 1841 router between the switch and firewall. This way, the firewall does not have to deal with routing of internal vlans. I am also assuming I would use access lists on the 1841 router to determine who has access to what VLANs. Am I correct in my assumptions? Which way is better? Is there a better way?
Secondly , we currently have vpn users from the internet terminating at the firewall to get into our network. In the new setup how would the firewall tell the router which vpn users belong to which vlans?
thanks
--------current setup-------------
internet
|
|
checkpoint firewall
|
|
layer 2 cisco switch
|
|
VLANS
--------new setup-------------
internet
|
|
checkpoint firewall
|
|
1841 cisco router
|
|
layer 2 cisco switch
|
|
VLANS
Secondly , we currently have vpn users from the internet terminating at the firewall to get into our network. In the new setup how would the firewall tell the router which vpn users belong to which vlans?
thanks
--------current setup-------------
internet
|
|
checkpoint firewall
|
|
layer 2 cisco switch
|
|
VLANS
--------new setup-------------
internet
|
|
checkpoint firewall
|
|
1841 cisco router
|
|
layer 2 cisco switch
|
|
VLANS