colly72 Posted November 24, 2015 Posted November 24, 2015 Hello all, I'm currently planning our schools migration from an ancient flat network, to a segmented, VLAN network. We've just about settled on HP Procurves for our core and edge switches and I'm reasonably comfortable on getting the VLANS set up and routing configured, together with subnets etc. Im undecided on whether to use ACLs to secure our inter plan traffic or whether to use our existing Sophos UTM firewall to achieve similar results. Does anyone have specific experience of using Sophos UTMs to do this or is using ACLs a better option? Thanks in advance. Michael
pantscat Posted November 24, 2015 Posted November 24, 2015 (edited) ACLs you'd generally use to stop certain types of traffic going between VLANs... whereas you'd use the Sophos UTM to stop traffic getting out/in to the whole network. EDIT TO ADD: unless of course you're using the Sophos UTM to do the routing between the VLANs... Edited November 24, 2015 by pantscat 1
Mr_Jiminy Posted November 24, 2015 Posted November 24, 2015 Not a Sophos UTM, but have used a Meraki MX security appliance. So I'd say the Sophos UTM is probably the best route. 1
Davit2005 Posted November 24, 2015 Posted November 24, 2015 If your Core switch is doing the IntervLAN routing then I'd use that to do your ACL's personally. 1
FN-GM Posted November 24, 2015 Posted November 24, 2015 (edited) It depends on your network design. If you have routed interfaces between your firewall and the switch you will need to use ACL's. If it is for a DMZ for example you should use 2 firewalls minimum and not ACL's. ACL's are no good for layer 7 traffic management. On the switches the ACL will not slow down your network. The switches use ASIC's and will go through the ACL's at wire speed. Also remember that unless you have really high end switches ACL's are BI Directional. So its no good for one way traffic. If you post your network diagrams we could advise more. ACLs you'd generally use to stop certain types of traffic going between VLANs.... Extended VLANS can. Edited November 24, 2015 by FN-GM 1
colly72 Posted November 24, 2015 Author Posted November 24, 2015 Thanks for the advice. I'll get the proposed network diagram uploaded here so you can see how it might look.
pantscat Posted November 26, 2015 Posted November 26, 2015 Extended VLANS can. Can what? Haven't had a coffee yet... am I being slow?
FN-GM Posted November 26, 2015 Posted November 26, 2015 Thanks for the advice. I'll get the proposed network diagram uploaded here so you can see how it might look. I was referring to the post I quoted directly above that statement
free780 Posted November 26, 2015 Posted November 26, 2015 You can do it by port as well. E.g just allow port 53 for DNS.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now