Re: IP addressing



jp,

You can create another ip network between switch and fw if you want to. In
that case create a routed interface on the switch port using IOS interface
config command 'no switchport'.

The second option would be to place fw interface in an existing vlan and
specify that vlan's SWI ip address as a next hop on your fw to reach
networks behind the switch.

B.R.
Igor


"jp" <siew@xxxxxxxxxxx> wrote in message
news:1125405075.251562.48600@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
> Hello,
>
> I have two 3560 switches and want to configure InterVlan routing.
> So I've searched for some help with my friend Google.
> And I find this :
> http://www.cisco.com/en/US/tech/tk389/tk815/technologies_configuration_example09186a008015f17a.shtml
>
> InterVlan routing works !!
>
> Well, I have put a firewall between the switch and the internet router.
> But I don't know which addresses I have to put on the switch and the
> firewall.
> Do I need to configure a new subnet (vlan) between the switch and the
> firewall ?
>
> Thanks for your help.
>
> Greetings
>
> JP
>


.



Relevant Pages

  • RE: Secure Network Design (DMZ, LAN, etc)
    ... You can't have separate subnets separated by a switch. ... is only because the firewall is going to be doing NAT in addition to ... > Subject: Re: Secure Network Design ...
    (Security-Basics)
  • Re: Home Network Setup Problem
    ... >> challenge of my own home network. ... Probably it is just a plain old switch ... Otherwise it will not hand packets from one network ... There is no firewall to complicate the setup. ...
    (freebsd-questions)
  • Xerox Docuprint 4512N - one problem and two questions
    ... Edimax 5-port switch 10/100 MB autosensing ... Why has "LPR byte count" to be enabled in the interface configuration? ... with ascii-debris preliminary to the next print job. ... How can I suppress the automatic printing of a network status page each ...
    (comp.sys.xerox)
  • config for securePlatform
    ... Cisco 3548XL Enterprise switch ... What I am trying to do is to utilize the VLAN feature so that I have ... one interface for all internal subnet's and one external interface. ... I am still not able to ping any adress in the network where the IP ...
    (comp.security.firewalls)
  • RE: Secure Network Design (DMZ, LAN, etc)
    ... 192.168.1.0/24 network and another one on the ... Any thoughts on the IPTables vs. a commercial firewall thing? ... You can't have separate subnets separated by a switch. ...
    (Security-Basics)