Avatar of cellulant
cellulant
Flag for Kenya asked on

juniper netscreen 5gt vlan tagging

hello experts,

I am using netscreen 5gt in trust - untrust mode.
Its indicated that It can support at least 10 vlan. I have some vlans communicating but I want all my data to go through  netscreen 5gt. If I configure the link from my catalyst to netscreen to be trunk, does it understand tagged data packets?
myswitch <=================>netscreen 5gt firewall <====================>clients switch


Network OperationsNetwork Architecture

Avatar of undefined
Last Comment
mikebernhardt

8/22/2022 - Mon
mikebernhardt

You cannot pass the vlan tags across your firewall. The purpose of the 802.1q support is to allow the firewall to connect to multiple subnets over 1 physical connection. After that it's Layer 3 only through the firewall policy.
mikebernhardt

The way to do it I guess is to set up a bunch of routes in the firewall so it knows which logical interface is the destination for the various traffic. But it all gets "mixed" once it is inside the firewall.
cellulant

ASKER
How can I make these vlans not to "mix". Does the mixing mean that there is a kind of data insecurity?
If I configure the the link to the firewall as trunk, is my switch still communicate to the switch on the other end?
How can I bring the Idea of native Vlans in such a situation?
This is the best money I have ever spent. I cannot not tell you how many times these folks have saved my bacon. I learn so much from the contributors.
rwheeler23
ASKER CERTIFIED SOLUTION
mikebernhardt

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.