Monday, February 19, 2018

Should all VLANs to firewall be tagged or send LAN as untagged? Best Practice?

Hi, currently I have 3 VLANS on my network (lan, wifi, guest). I'm passing all of these to my firewall as tagged vlans at the moment. Is this fine or should I rather be sending my default/LAN traffic as untagged?

I read here that for cisco switches it is recommended to change the default vlan for security reasons. I assume what I'm doing is similar from a security perspective?

PS: I'm using one of the other ports on the firewall as a management port if i ever need to make changes to the VLANs that would break my network access on the lan VLAN



No comments:

Post a Comment