Avatar of activateahsd
activateahsd
 asked on

Draytek firewall just for wireless management behind Sonicwall Gateway Firewall

Hi
Can i have a Draytek Vigor 2860 behind another firewall?
The reason I am asking is that the company are going to upgrade the firewall to a Sonicwall Next Gen firewall but the existing firewall (the Draytek) manages the wireless access points so i want to keep it on the the network if possible but just for that task rather than for its 'firewall abilities'.
Can this be done?

Thanks,
Andrew
Hardware FirewallsNetworking

Avatar of undefined
Last Comment
activateahsd

8/22/2022 - Mon
J Spoor

you could hookup the draytek to one of the extra ports on the SonicWall.
then use the draytek as a router to the LAN

you will have to add a route ont he Sonicwall fo rthe subnet behind the draytek
activateahsd

ASKER
So the Draytek would sit between the Sonicwall and the switch?
Can it be done so the Sonicwall goes into the Switch and the Draytek just comes off the Sonicwall independantly (but on the same LAN subnet)?
Reason being that i dont want the Draytek to be a point of failure that could affect the whole network.

Thanks
Andrew
J Spoor

from a security perspective, you would always put WLAn on a different security zone.

well optionally you can also put the draytek on the same lan as the SonicWall and leave it's WAN port disconnected.
If it's a DHCp server for the WLAN make sure to provision the SonicWall's IP address instead of the draytek.

Perhaps easier, but dfinlety less secure...
All of life is about relationships, and EE has made a viirtual community a real community. It lifts everyone's boat
William Peck
activateahsd

ASKER
OK thanks, that makes sense, if the WAN port is disconnected then i guess the firewall within the Draytek is redundant?

Thanks
Andrew
ASKER CERTIFIED SOLUTION
J Spoor

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
activateahsd

ASKER
great thanks