Question

Direct VLAN traffic to 2 different firewalls

  • 6 January 2021
  • 6 replies
  • 53 views

We are setting up 2 firewalls for internet access via 2 individual circuits.  Currently our default route sends all traffic to firewall #1.  We are looking to send all traffic from a single VLAN to the new firewall (firewall #2) and all other VLANS to firewall #1.  How do I set up a routing configuration for this?


6 replies

Userlevel 5

Which switch is in use?

One possibility would be flow-redirect: https://extremeportal.force.com/ExtrArticleDetail?an=000083175

Userlevel 6
Badge +1

Hi,

There are a lot of option possible.

A topology diagram will help to give advise.

Mig

Here is the basic network topology that we have with the new firewall addition

Userlevel 5

The BlackDiamond is the router (the VLAN-Interfaces are on the BlackDiamond?) and routes the traffic to the firewalls?

In this case you could use different VRs or use flow-redirect IMO.

This is correct Stephan K.  I will look into flow-redirect with different VRs.  Thank you.

Userlevel 5

This is correct Stephan K.  I will look into flow-redirect with different VRs.  Thank you.

If you use different VRs you don’t need flow-redirect. You can simply create two default-routes, one for each VR.

Reply