Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

VLANs with zone based firewall best practises.

Status
Not open for further replies.

creeping666

Technical User
Jan 21, 2009
24
NZ
I'm not sure how to setup VLANs with a zone based firewall:



Scenario
--------

On the network there are:

1) Common devices that all VLANs need access to (printers, scanners ...)
2) Servers that only some VLANs need access to (sales, admin, production ...)
3) Guest VLANs that should only have access to the common devices VLAN



Sample network
--------------

- 2950 swicth trunked to a router with sub interfaces or SVI's and IP routing enabled. (router on a stick)
- The switch and router have the same VLAN's.



Questions
---------

1) Would you put each VLAN in its own zone and then setup zone pairs between them?
If so, it seems like a lot of almost double up configuration if there were lots of VLANs

Is there a better way to do it?

Thanks.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top