- Posts: 91
- Thank you received: 0
Netscreen ISG 2000
We have a network in which all the traffic from 70 Foundry's FastIron switches are connected through fiber optic cables to a centeralized Foundry's BIGIron 15000 Layer 3 Switch. Two Netscreen ISG 2000 firewalls are also connected through tht bigiron switch along with 60 Servers( Mail,Database,MOM, Web servers etc) .
Now our aim is to pass all the traffic from Fastiron edge switches through the Bigiron 15000 switch and route this traffic to Netscreen FWs so tht IPS feature of Netscreen can b utilized to generate logs and stuff like tht.and then traffic should be transmitted to their intended destinations ( either those 60 Servers or back to edge switch clients etc ) .
We wanto use Netscreen FW in layer2 (transparent mode) alongwith its IPS features .I wana b sure if it can b done or not.If it cant then we'll hav to route all the traffic through Netscreen's routing engine instead of BIGIron foundry switch and it will make us work BigIron layer 3 switch as a layer 2 switch (which i dunt wana do).
Whts the best way to route the traffic ?
Our main requirement is to pass through all the traffic from fastiron edge switches to the Netscreen FWs and then to route it to their intended destination.Below is the network layout
FW #1
PCs----EdgeSwitch#1
\ /
BigIron Switch---FW#2
/ / \
/ Srv1 ......Srv60
PCs---EdgeSwitch#2--- /
| /
| /
PCs--EdgeSwitch#70
where Edgeswitch= Foundry's Fastiron switches
Where FW = Netscreen ISG 2000
Rgds
Taqqi
Hi Guys!
We have a network in which all the traffic from 70 Foundry's FastIron switches are connected through fiber optic cables to a centeralized Foundry's BIGIron 15000 Layer 3 Switch. Two Netscreen ISG 2000 firewalls are also connected through tht bigiron switch along with 60 Servers( Mail,Database,MOM, Web servers etc) .
Now our aim is to pass all the traffic from Fastiron edge switches through the Bigiron 15000 switch and route this traffic to Netscreen FWs so tht IPS feature of Netscreen can b utilized to generate logs and stuff like tht.and then traffic should be transmitted to their intended destinations ( either those 60 Servers or back to edge switch clients etc ) .
We wanto use Netscreen FW in layer2 (transparent mode) alongwith its IPS features .I wana b sure if it can b done or not.If it cant then we'll hav to route all the traffic through Netscreen's routing engine instead of BIGIron foundry switch and it will make us work BigIron layer 3 switch as a layer 2 switch (which i dunt wana do).
Whts the best way to route the traffic ?
Our main requirement is to pass through all the traffic from fastiron edge switches to the Netscreen FWs and then to route it to their intended destination.Below is the network layout
FW #1
PCs----EdgeSwitch#1
\ /
BigIron Switch---FW#2
/ / \
/ Srv1 ......Srv60
PCs---EdgeSwitch#2--- /
| /
| /
PCs--EdgeSwitch#70
where Edgeswitch= Foundry's Fastiron switches
Where FW = Netscreen ISG 2000
Rgds
Taqqi