We're moving our wireless stuff, among other things, to a VLAN separate from the wired workstations. Routing and access is processed on the 6509 with the FWSM.
We also have remote offices (PIX 501's) connected via ipsec to a PIX
520 dedicated to this task. My question is, is there a way to pass 801.2Q tagged packets over the ipsec tunnel, and split them out with a switch on the other end? I can present the PIX520 with access ports or a trunk of course, but I'm not clearly thinking when it comes to sorting them out. The remote sites currently each have their own subnet, but we're likely going to need 3 VLANs represented in the remote sites and this seems like the administrative overhead of access-lists and routing could get out of control very quickly.Any thoughts anyone?
Thanks, Joey