Hi,
I have some design questions regarding Campus networks and firewalls. If I have a Campus Core consisiting of 2 x L3 switches and I directly connect an HA pair of perimeter firewalls to each core switch (each firewall being connected to both core switches), I am unsure how routing of traffic will work.
The Firewalls use HSRP/VRRP for HA so the connections from the core to the firewalls must be L2 trunks? Does this mean I would have to create a VLAN on the core switches and trunk this VLAN across both core switches? Then both core switches would have a default route of the HSRP address of the firewalls?
Would it be better to connect the firewalls to the core switches using L3 connections and run an IGP on the firewalls? How would this work in practice?
Any recommendations or advice would be appreciated.
Regards, Nick