We newly purchased a Cisco Catalyst 3560G-24-EMI that will be a core layer 3 switch to route between 3 vlans (at 3 distinct locations that separately link to an ISP switch by fiber optics) and to use a trunk port to carry vlan traffic to the ISP's switch.
The following is the basic network map:
site1---------------ISP switch ------------- site 2 vlan 102 | | vlan103
192.168.1.0/24 | | 192.168.2.0/24 | | trunk (dot1q) | | | | native vlan101; | | vlan104 - 192.168.3.0/24Site 3(Headquarter) Core L3 switch 3560G (192.168.3.1) | PIX 506E (192.168.3.2)
We also have a PIX 506E available in site 3 to control the Internet traffic.
My questions lie in the two areas:
- Physically where should I install the PIX? --my understanding is I should link both interfaces of the PIX to two ports of the 3560G, one interface for inbound and the other for outbound. The two ports on the switch that connect to the PIX should not be assigned to any vlan. Thus I don't need to configure anything about vlan on the PIX to allow vlan tagging traffic.
- Do site 1 and site 2 have to be configured vlan information on their access layer switches? Regarding the ISP engineer's opinion, we don't need configure vlan on switches on site 1 and site 2 because the ISP switch has already assigned two ports to vlans that belong to the two sites. Is this true? If not, we have to consider purchasing two layer 2 switches (such as 2960) to fulfill the task.
Thank you so much for your help on the two questions.