All,
Thanks for the help in advance.
I am thinking about using the catalyst switch in its promiscuous mode so I can segregate network connections for different servers. Others have expressed using DMZs on the firewalls for this.
What would be the major advantages and disadvantages of using either method?
If I use the multiple DMZ method, then I would have to get another switch where I have my DMZ VLANs created and somehow connect this switch to the internal network. But how would each DMZ know how to basically "converge" back to the internal network. Would it be on the firewall where this config would be placed? Would the fw have a lan connections and all DMZs it regulates filters to the lan connection?
If I use a catalyst switch in promiscuous mode, I can essentially segregate each network port as its own "DMZ" since each port is not suppose to know one another.
Any one have any ideas as to which method is preferred.
Thanks!!