This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Best practice location for vlan interfaces

Hi everyone,

we have a common setup: 

Huawei access switches -> Huawei Core switches -> Sophos Firewall XG.  

Most of the VLAN interfaces are located on the core switches, which makes it difficult to control or monitor traffic with the XG.  

Should I move every Vlan interface from core switch to the firewall? 

Thanks for the help!

Kristof 



This thread was automatically locked due to age.

Top Replies

  • I would not recommend it because of many reasons

    - performance bottleneck:  (you literlly throttling down your network to interface speed, throughput and other factors of the firewall)

    - single point of failure: if your firewall go down, your intervlan/intervrf traffic is interrupted 

    - feature lack: firewall does not support broadcast forwards for stuff like WoL, PXE Boot etc, complex multicast routing, VRFs, 

    - maintainance: sophos lifecycle requires you to upgrade always to the newest code, otherwise you won't get "support". in larger networks thats a pain in the neck, if your intervlan routing is on the firewall.

    if your goal is just visibility, there are better ways eg. netflow from the switches. 

    Jump to answer
Parents Reply Children
No Data