Thursday, October 25, 2018

Question: Virtual FW and Router inline - How to isolate multiple vlan trunks on one dSwitch

Hello Reddit,

Posted in /r/vmware and received a negative answer so I'd like to have your opinion about this:

I'm learning vmware networking with my lab at home.

I want to use a virtual Check Point security gateway in L2 mode to filter inter-vlan traffic before it reaches a virtual VyOS router.

Basically:

VMs <---> dSwitch <---(vlan trunk)---> Check Point FW (L2 mode) <---(vlan trunk)---> dSwitch <---(vlan trunk)---> Vyos Router <---> dSwitch <---> Internet

With this configuration, I use 3 dSwitchs and minimum of 3 uplinks.

I guess that's because I can't find a way to isolate multiple vlan trunks on only 1 dswitch and force the traffic coming from the VMs to enter the firewall first and proceed to the router.

Any ideas if it's possible to use only one dswitch ?

In a previous exercise, I was able to achieve this with physical equipment. Check Point was running on a DL380 and I bridged the built-in nics.



No comments:

Post a Comment