[j-nsp] J-series stateful firewall / NAT architecture

Amos Rosenboim amos at oasis-tech.net
Sun Apr 20 17:16:09 EDT 2008


I Indeed mean using VLAN separation. Although this is considered not  
a good practice for this scenario, mainly because of VLAN hopping and  
other L2 attacks, considering that there are L3 devices connected to  
this switch from all directions it does not look as a too big of a risk.

Of course the 4 switches option is preferred if the budget allows it.

Amos

On Apr 19, 2008, at 7:56 PM, Florian Weimer wrote:

> * Amos Rosenboim:
>
>>
>> Regarding the number of boxes, you can consolidate the 4 switches to
>> just two by using vlans.
>
> Huh?  You either lose redundancy, or you heavily rely on VLAN
> separation on those switches.  Neither seems to be a good idea.
>
> -- 
> Florian Weimer                <fweimer at bfk.de>
> BFK edv-consulting GmbH       http://www.bfk.de/
> Kriegsstraße 100              tel: +49-721-96201-1
> D-76133 Karlsruhe             fax: +49-721-96201-99



More information about the juniper-nsp mailing list