LAN Design with ASA 5540

Posted on 2009-02-10
Last Modified: 2012-05-06
Preparing to re-architect a LAN with 100 users (150 projected).

Currently have an ASA 5540 in place as the firewall, router, web filter, and IPS.
Only the outside and inside interfaces are configured.  Inside is connected to an HP switch stack that connects all servers and clients.

Requirements for new architecture:

-Create DMZ to house proxy server and other web servers as company grows.
-Segment all conference room drops to have outside only internet access.  No connectivity to servers on LAN.
-Create 2 VLANs.  1 for Servers. 1 for Workstations.  Workstations will be DHCP clients on a different subnet than servers which will be statically assigned IPs.

I have a Cisco 3560G-48PS unused, will be purchasing 2 more of the same.  Possibly 3.

1. Should the DMZ be created using a separate switch connected to one of the unused interfaces on the ASA?
2. Should the "outside access only" workstations have their own switch connected to an open interface on the ASA, or will VLANing off 10 ports on one of my existing switches be more efficient?
3. For this number of users, would it be recommended to purchase an interior router, or will the ASA be able to handle routing duties sufficiently?

Thank you for any input.

Question by:tpearson1
    1 Comment
    LVL 43

    Accepted Solution

    1.  Yes, ideally, you would have a separate physical switch hanging off the DMZ interface for DMZ servers, devices, etc.  However, having a separate VLAN for the DMZ off your internal switches that the Firewall DMZ interface is part of would work also but is less ideal.  Trade off between security and cost.

    2.  Again, ideally, this would be the case but it may not be the easiest to accomplish if you are looking to have "Internet only" ports physically available anywhere in the network.  Having a separate VLAN extended to every edge switch would be sufficient for security but also ease management (less cabling).  Alternatively, if you don't want to use a Firewall interface for this purpose, you can use a separate "Internet only" VLAN and use access-lists to restrict access from these hosts to only the Internet.  In this case a separate interface on the Firewall would not be used.  Access would be controlled with a VLAN at layer2 and an access-list at Layer3 on the VLAN interface (in the case of using a 3560 as the VLAN router).

    3.  If you plan on getting 3560G switches, I would use one (or two if desiring redundancy) as the interior router.  The 3560G at the "core" would do routing between VLAN's and aggregate the trunks from the edge/access switches.  The ASA would be the 3560's default gateway.  I try to avoid intra-interface routing on an ASA if at all possible.

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    What Should I Do With This Threat Intelligence?

    Are you wondering if you actually need threat intelligence? The answer is yes. We explain the basics for creating useful threat intelligence.

    This article is focussed on erradicating the confusion with slash notations. This article will help you identify and understand the purpose and use of slash notations. A deep understanding of this will help you identify networks quicker especially w…
    If you are thinking of adopting cloud services, or just curious as to what ‘the cloud’ can offer then the leader according to Gartner for Infrastructure as a Service (IaaS) is Amazon Web Services (AWS).  When I started using AWS I was completely new…
    After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
    After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

    737 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    22 Experts available now in Live!

    Get 1:1 Help Now