Link to home
Start Free TrialLog in
Avatar of hermanazefor
hermanazefor

asked on

DMZ SWITCH

I have a dmz switch (3560) running in our network. Now we have a single point of failure and I wish to add a second switch. I am running private-vlan scheme. I want to configure a trunk port using sfp gigabit interface. Please should I do a private vlan mapping on my trunk port.
Should my primary interface on the new switch have a different ip address.
 
Thanks
Avatar of clonga13
clonga13

It depends on what your doing. Are there multiple VLANs on your DMZ? where is the firewall located in relation to these switches. If your just trying to add a second switch for disaster recovery purposes or more capacity, then just configure a trunk between the two switches with a cross over cable between them.
Avatar of hermanazefor

ASKER

I am doing a direct connection between my two 3560 using fiber gbic. I have multiple private vlans and a two regular vlans. Would it be prudent to just configure a port without mapping the private vlans via the trunk and do I need a different ip address for this new switch or just a replica of my other switch.

Thanks
ASKER CERTIFIED SOLUTION
Avatar of clonga13
clonga13

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial