Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Best practice location for vlan interfaces

Hi everyone,

we have a common setup: 

Huawei access switches -> Huawei Core switches -> Sophos Firewall XG.  

Most of the VLAN interfaces are located on the core switches, which makes it difficult to control or monitor traffic with the XG.  

Should I move every Vlan interface from core switch to the firewall? 

Thanks for the help!

Kristof 



This thread was automatically locked due to age.
Parents
  • I would not recommend it because of many reasons

    - performance bottleneck:  (you literlly throttling down your network to interface speed, throughput and other factors of the firewall)

    - single point of failure: if your firewall go down, your intervlan/intervrf traffic is interrupted 

    - feature lack: firewall does not support broadcast forwards for stuff like WoL, PXE Boot etc, complex multicast routing, VRFs, 

    - maintainance: sophos lifecycle requires you to upgrade always to the newest code, otherwise you won't get "support". in larger networks thats a pain in the neck, if your intervlan routing is on the firewall.

    if your goal is just visibility, there are better ways eg. netflow from the switches. 

Reply
  • I would not recommend it because of many reasons

    - performance bottleneck:  (you literlly throttling down your network to interface speed, throughput and other factors of the firewall)

    - single point of failure: if your firewall go down, your intervlan/intervrf traffic is interrupted 

    - feature lack: firewall does not support broadcast forwards for stuff like WoL, PXE Boot etc, complex multicast routing, VRFs, 

    - maintainance: sophos lifecycle requires you to upgrade always to the newest code, otherwise you won't get "support". in larger networks thats a pain in the neck, if your intervlan routing is on the firewall.

    if your goal is just visibility, there are better ways eg. netflow from the switches. 

Children
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?