GESTIONVAL ODNODN INFRASTRUCTURE Technical Inquiry

Firewall to Core Switch

Best practice is to use dedicated LACP port channels with 802.1Q trunks for VLANs, leveraging VRFs for segmentation and keeping routing on the core switch for performance while the firewall enforces security.Physical and Logical Connectivity

For high availability (HA) firewalls, establish two separate LACP port channels from the core switch: one to the active firewall and one to the standby firewall. Each port channel should be configured as an 802.1Q trunk carrying all required VLANs, including transit VLANs for VRFs and any Layer 2 VLANs routed on the firewall . If the firewall is performing inter-VLAN routing for certain VRFs, extend those VLANs at Layer 2 from the core to the firewall .

VLAN and VRF Considerations
  • Transit VLANs: For each VRF routed on the core switch, define a dedicated transit VLAN to the firewall. This allows the firewall to act as the next-hop for static routes while maintaining logical separation .
  • Trunking: Core switch interfaces connecting to the firewall should be trunks, allowing all VLANs to pass. Subinterfaces on the firewall can then handle routing per VLAN .
  • VRFs: Use VRF-lite to segment traffic for internal, guest, or cloud services. This ensures isolation without duplicating physical hardware .
Routing Strategy
  • Core Switch Routing: Perform Layer 3 routing on the core switch for high-throughput east-west traffic. This reduces the load on the firewall and avoids bottlenecks .
  • Firewall Routing: Delegate routing to the firewall only for traffic requiring inspection, security enforcement, or inter-VRF routing that the core does not handle .
  • Default Routes: Avoid placing default routes on the core for all traffic unless necessary; instead, use static routes pointing to the firewall for specific VRFs .
Management Access
  • Out-of-Band Management: Connect firewall management ports to a dedicated management VLAN to separate administrative traffic from production traffic .
  • FMC or FDM: Depending on whether the firewall is centrally managed (FMC) or locally managed (FDM), configure access accordingly to ensure secure and reliable management.
Performance and Resilience
  • High-Speed Links: Use 10G, 40G, or 100G links between core switches and firewalls to handle high-throughput traffic .
  • HA Considerations: Ensure each firewall in an HA pair has independent physical connections to the core to prevent single points of failure .
  • Simplified Troubleshooting: Dedicated port channels for each firewall reduce complexity and improve failover response times .
Summary

The optimal design balances performance and security: the core switch handles high-speed routing and VLAN segmentation, while the firewall enforces security policies and inspects traffic. Using trunked LACP port channels, VRFs, and dedicated management VLANs ensures a resilient, scalable, and secure integration between the core switch and firewalls .

Firewall to Core Switch

Recommendation for a connection between Core Switch and Firewall

Solved: Hello, I am asking myself what others recommend for the connection between core switch and Firewall. The

Solved: Connectivity from Core to Firewall

If the test vlan ony needs access to the Palo Alto firewall and nothing else then don''t use an SVI on the core switch,

Routing on firewall or core switches? : r/networking

Traffic staying within a zone can be routed on the core switch to reduce load on the firewall and improve performance. So in your

Gateways on Core Switch vs Firewall : r/networking

This is going to depend on what your firewall can handle. I would keep all of the gateways on the switches so the firewall doesn''t

When to Route on Core Switches vs Next-Gen Firewalls in Enterprise

Learn when to use core switch routing vs next-generation firewall routing in enterprise networks. Explore performance, security

Network Setup for core and firewall

The best way from a security standpoint is to have a physically separate switch connecting the ISP handoff to the

Small Office Network Setup with Fortinet Firewall & Core Switch

In this video, I demonstrate how to configure a Fortinet Firewall in a small office network setup using a core switch.

move vlans off firewall to core switch

When you move VLANs from the firewall to the switch, the important thing to remember, is you have to add static

Core layer | FortiSwitch 7.6.0 | Fortinet Document Library

With 8x100-GbE QSFP28 slots per FortiGate unit, it provides enough capacity to directly connect with 2x100-GbE ports to each of

switching

I have been assigned for my first project ever as network engineer, things seems to be going smoothly, but there''s

Firewall to 2 core switches

The distribution switches are Cisco Catalyst 3850-24XS and the Core switches are Cisco

ISP Hooked Up to Core Switch First... Instead of Straight to

They''ve just pinched some ports on the core switch to use as an intermediary switch between you firewall/router, it''s a simple way of

Recommendation for a connection between Core Switch and Firewall

Hello, I am asking myself what others recommend for the connection between core switch and Firewall. The setup is

L3 Core to Firewall question

The current network design consists of a firewall (Fortigate 100D), a pair of stacked "network core" L3 switches (Netgear M4300)

Connecting two buildings with a Core Switch and Fortigate Firewall

I have a cisco core switch 4500 on one building and access switches 2960 POE about five switches and it connects to

Internet Connection Termination: Core Switch vs Firewall

In cases where there''s a HA firewall setup, I believed that, instead of introducing another switch between the ISP and the firewall

Network Segmentation

You will only need a transit VLAN/subnet between the firewall and the core. If you can do that with a 10 Gbps interconnect between

How to Configure OSPF Between Firewall and Core Switch | Step-by

In this video, we configure OSPF routing between a Core Switch and a Firewall and

Should I build a VLAN between firewall and core layer 3 switch?

This firewall hangs directly off of our core, layer 3 routing switch. (See Current Configuration image below.) My

Moving VLANs from Core Switch to Firewall : r/networking

We have a school network currently running on a Cisco ASA 5516-X connected to a 9200L acting as a core switch, with VLAN

Single firewall connect to 2 core switches

Yes, firewall will create an aggregation port and assign an ip address, and connect to 2x layer 2 switches (Cisco

networking

Router port facing to Core switch is running trunk mode allowed vlan 200 & 300. I am placing a firewall between the

Connection Between Core and Firewall

Dears, Please find the attached Please suggest when 6509 are in VSS mode how the connection should be. The

Connecting Layer 3 Switch to Firewall

How to connect Layer 3 Switch to Firewall on Huawei products. You also can contact

Single firewall with 2 core switches

Hi All Following is my requirement. Two different WAN links get connected to the firewall via two routers.(Different ip

Firewall to Network Switch Implement

My firewall is Fortigate 201F. So, with the HA failover I only have to configure on my firewall site? Why I want to do

Can I place a firewall behind the core switch with a public ip

I had a client with 3 locations and Comcast Metro E homerunning between the sites and their HQ, which had the

Core layer | FortiSwitch 7.6.0 | Fortinet Document Library

The core layer is critical, yet very simple to design, and allows for network evolution quite easily. Point-to-point links are used

Firewall or Switch for routing?

Replacing UTM and Switches. Firewall/UTM is Watchguard XTM 515 Switches are HP1910 48G (core) and HP 1910

How to Configure a Firewall in Cisco Switch?

A firewall is a type of network security device component that is used to keep track of incoming and outgoing network

Firewall to 2 core switches

The distribution switches are Cisco Catalyst 3850-24XS and the Core switches are Cisco

ISP Hooked Up to Core Switch First... Instead of Straight to

They''ve just pinched some ports on the core switch to use as an intermediary switch between you firewall/router, it''s a simple way of

Recommendation for a connection between Core Switch and Firewall

Hello, I am asking myself what others recommend for the connection between core switch and Firewall. The setup is

L3 Core to Firewall question

The current network design consists of a firewall (Fortigate 100D), a pair of stacked "network core" L3 switches (Netgear M4300)

Connecting two buildings with a Core Switch and Fortigate Firewall

I have a cisco core switch 4500 on one building and access switches 2960 POE about five switches and it connects to

Internet Connection Termination: Core Switch vs Firewall

In cases where there''s a HA firewall setup, I believed that, instead of introducing another switch between the ISP and the firewall

Connecting internet uplink to switch or firewall

We can add more resiliency by adding another core switch so 1 firewall and 1 internet connection to one core switch and the other

What is the best practices for Users Getaway! Core Switch or Firewall

Dear Experts, I am wondering what is the best practices for the user getaway. is Core Switch preferred to be the

When to Route on Core Switches vs Next-Gen Firewalls in Enterprise

Learn when to use core switch routing vs next-generation firewall routing in enterprise networks. Explore performance, security

What''s the general purpose of having your core switch connect

What''s the general purpose of having your core switch connect to a firewall for internet AND directly to the internet on a different port

Network Segmentation

You will only need a transit VLAN/subnet between the firewall and the core. If you can do that with a 10 Gbps interconnect between

How to Configure OSPF Between Firewall and Core Switch | Step-by

In this video, we configure OSPF routing between a Core Switch and a Firewall and perform complete failover testing

Should I build a VLAN between firewall and core layer 3 switch?

This firewall hangs directly off of our core, layer 3 routing switch. (See Current Configuration image below.) My

Moving VLANs from Core Switch to Firewall : r/networking

We have a school network currently running on a Cisco ASA 5516-X connected to a 9200L acting as a core switch, with VLAN

Recommendation for a connection between Core Switch and Firewall

Solved: Hello, I am asking myself what others recommend for the connection between core switch and Firewall. The

Solved: Connectivity from Core to Firewall

If the test vlan ony needs access to the Palo Alto firewall and nothing else then don''t use an SVI on the core switch,

Routing on firewall or core switches? : r/networking

Traffic staying within a zone can be routed on the core switch to reduce load on the firewall and improve performance. So in your

Gateways on Core Switch vs Firewall : r/networking

This is going to depend on what your firewall can handle. I would keep all of the gateways on the switches so the firewall doesn''t

When to Route on Core Switches vs Next-Gen Firewalls in Enterprise

Learn when to use core switch routing vs next-generation firewall routing in enterprise networks. Explore performance, security

Network Setup for core and firewall

The best way from a security standpoint is to have a physically separate switch connecting the ISP handoff to the

Small Office Network Setup with Fortinet Firewall & Core Switch

In this video, I demonstrate how to configure a Fortinet Firewall in a small office network setup using a core switch.

move vlans off firewall to core switch

When you move VLANs from the firewall to the switch, the important thing to remember, is you have to add static

Core layer | FortiSwitch 7.6.0 | Fortinet Document Library

With 8x100-GbE QSFP28 slots per FortiGate unit, it provides enough capacity to directly connect with 2x100-GbE ports to each of

switching

I have been assigned for my first project ever as network engineer, things seems to be going smoothly, but there''s

Recommendation for a connection between Core Switch and Firewall

Solved: Hello, I am asking myself what others recommend for the connection between core switch and Firewall. The

Solved: Connectivity from Core to Firewall

If the test vlan ony needs access to the Palo Alto firewall and nothing else then don''t use an SVI on the core switch,

Routing on firewall or core switches? : r/networking

Traffic staying within a zone can be routed on the core switch to reduce load on the firewall and improve performance. So in your

Gateways on Core Switch vs Firewall : r/networking

This is going to depend on what your firewall can handle. I would keep all of the gateways on the switches so the firewall doesn''t

When to Route on Core Switches vs Next-Gen Firewalls in Enterprise

Learn when to use core switch routing vs next-generation firewall routing in enterprise networks. Explore performance, security

Network Setup for core and firewall

The best way from a security standpoint is to have a physically separate switch connecting the ISP handoff to the

Related Video Reference

This video was associated with the source search result. Verify technical details against current product documentation and project requirements.

Technical note

This reference is intended for preliminary ODN and passive infrastructure research. Topology, split ratio, box or cabinet capacity, closure rating, cable type, test limits and applicable standards must be verified for the specific project.

Still Have a Technical Question?

Use the inquiry form to describe an ODN network, passive component or distribution box question.

Start an Inquiry