Help with network design

Technical Information
Technical Information used Ask the Experts™
on
Hi

I have a network with a Layer2 link back to a datacentre which provides our internet connection, we have no firewall onsite at present but looking to install one.

We have ordered an internet connection on premise.

We want to keep our Layer 2 connection and make use of it somehow.

We want to use the new internet connection on-premise and a firewall to route the internet. What's the best way to do this?
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
bbaoIT Consultant

Commented:
> I have a network with a Layer2 link

what do you actually mean with a L2 link? MPLS from on-premise  to the data center?
Network Architect
Commented:
The thing you want to do . is to use the L2 link to do traffic that needs to go to the Datacenter, and you will use the Firewall/router to route traffic to internet over the Internetlink and the "datacenter" traffic over the L2 link.

When you want to split traffic like this is best to do it with a small firewall with the atleast 3 interfaces . one to internet, one to L2 link , one to LAN.
@bbao yes exactly  MPLS from on-premise  to the data center

@aamodt OK great, so I should remove the routing from my Layer3 node?
Ensure you’re charging the right price for your IT

Do you wonder if your IT business is truly profitable or if you should raise your prices? Learn how to calculate your overhead burden using our free interactive tool and use it to determine the right price for your IT services. Start calculating Now!

Jim BattleDriver

Commented:
Yes, remove the routing from your Layer3 node
How about if that isn't an option for me?
Thomas AamodtNetwork Architect

Commented:
guess you can connect the firewall infornt of the layer3 node . and have a "default" route from Layer3 node to the firewall.
and then on the firewall you split the traffic out to L2 link or the "World/internet".

If that makes somewhat sense.

But best is to skip the extra hop if posible.


you can also do like use Firewall for internet traffic and the layer3 node for L2 traffic.
I have kindof that solution on one instance in our network.
Yes thats what I'm looking for, Firewall for Internet traffic and layer3 node for L2 traffic.
SouljaSr.Net.Eng
Top Expert 2011

Commented:
Leave the "Layer 3 Node" I assume is a layer 3 switch in place, so you can use the Layer 2 Link to the DC for a backup internet. Use the new firewall for your primary internet.

I would just place a higher metric on the default route on the Layer 3 switch pointing to the DC, and add a lower metric default route to pointing to the firewall.

Add a /30 between the layer 3 switch and firewall. If you have any additional questions. Message me.
bbaoIT Consultant

Commented:
>  MPLS from on-premise  to the data center

can we know what physical devices are there at the two ends of your MPLS running from your office to the data center?

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial