[f-nsp] Route between vlans in same subnet on BigIron

Rutger rutgermm at xs4all.nl
Fri Jun 8 19:17:25 EDT 2007


Hello,

I'm looking for a solution that I can place a firewall between 2 vlans on
a BigIron router with L3 enabled.

For this moment there is one big vlan2 with a ip-route 0.0.0.0 0.0.0.0
123.123.123.123 and a router-interface ve2 with the IP of the router, the
address I use as gateway on the machines behind it.

The WAN port has the IP address to communicate with to the GW of the
carrier-router (123.123.123.122)

Because I want to let the BigIron the routing I was thinking of 2 vlans,
one for the lan-vlan and one for the wan-vlan, but this will be a problem
because I only have one IP-block what I can use.

So the sitiuation must be as follow on the BigIron:

WAN => vlan2 => firewall => vlan3(lan)

Because of the fact that the firewall will be transparent, this should be
no problem to place it between the vlans. The actual problem is how to
manage this. In simple words, I should be able to replace the firewall
with a cross-cable and it should still work.

Cisco for an example has a SVI solution for this, but I can't find such
thing for a Foundry router.

Can someone give me some advise or examples ?





More information about the foundry-nsp mailing list