Jump to content

Recommended Posts

Posted

SM.png

 

I'm looking at something like this,

i'm wondering whether to

 

1.use the smoothwall(s) as the default gateway for all vlans

or

2.use the x670's as the default gateway and add routing entries for all internal vlans then a default route to the smoothwall

Posted
Use the IP address of the VLAN as the default gateway for each VLAN. On the switch setup a static route with the IP of the smoothwall box.
Posted
you mean 2. use the x670's, this is the direction i have been leaning towards

 

No in option 2 you said use the IP address of the x670. I mean use the IP address on the VLAN you have configured on the switch.

Posted
No in option 2 you said use the IP address of the x670. I mean use the IP address on the VLAN you have configured on the switch.

 

yes the address of the vlan on the x670???????????????

Posted
sorry i see what you mean. I meant in configuring the routing table on the switch

 

How do you mean? On the switch you set a static route to point to smoothwall.

 

So from a client tracert it would go like this

 

Computer > VLAN IP > Smoothwall IP

Posted
How do you mean? On the switch you set a static route to point to smoothwall.

 

So from a client tracert it would go like this

 

Computer > VLAN IP > Smoothwall IP

 

ignore that post, i'm tired.

 

No in option 2 you said use the IP address of the x670. I mean use the IP address on the VLAN you have configured on the switch.

 

yes i mean the ip address of the VLAN on the x670

Posted

still wondering whether to give the smoothwall box an interface on each vlan that needs internet access or route (seperate question to default gateway of device)

this would save hitting the x670 with having to route internet traffic.

Posted

Thats right (talking about post 9). The IP address on the switch is just for management nothing else.

 

I wouldn't do an interface for each VLAN, you wont benefit. Just configure smoothwall with all the IP ranges of your vlans and put the static route on the switch.

Posted (edited)
Thats right (talking about post 9). The IP address on the switch is just for management nothing else.

 

I wouldn't do an interface for each VLAN, you wont benefit. Just configure smoothwall with all the IP ranges of your vlans and put the static route on the switch.

 

thank you, i was coming the same conclusion, especially give the internet pipe is 100mb and the switches are 10gbe. i think smoothwall should get its own vlan then, as it seems a little weird for it to be on one vlan with clients and then the other vlans have to route to get to it.

 

tbh i'm thinking out loud as i have limited time "in the building" to set this up and its probably going to playing on my mind until its done, luckily i have one of the smoothwalls at home so I can get that ready then go and "throw it in the rack"

Edited by ConradJones
Posted
I have a premier firewall VLAN as well. I think its the right way to go.

 

Yes I agree strongly with this. Internet facing devices (and BYOD) should be in a DMZ vlan.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...