<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 2960X - WAN and DMZ on same switch separated by vlans? in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/2960x-wan-and-dmz-on-same-switch-separated-by-vlans/m-p/389527#M1084</link>
    <description>&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;the title says it pretty much. Trying to consolidate a 24 port switch that only uses 3 ports with another 24 port that is only using 2 ports.&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;How safe/comfortable would you be if you used the same switch for DMZ and WAN traffic, but separate them by VLAN, and strict access trunks to a firewall?&lt;/P&gt;</description>
    <pubDate>Thu, 02 Dec 2021 00:34:56 GMT</pubDate>
    <dc:creator>Joshua2215</dc:creator>
    <dc:date>2021-12-02T00:34:56Z</dc:date>
    <item>
      <title>2960X - WAN and DMZ on same switch separated by vlans?</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/2960x-wan-and-dmz-on-same-switch-separated-by-vlans/m-p/389527#M1084</link>
      <description>&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;the title says it pretty much. Trying to consolidate a 24 port switch that only uses 3 ports with another 24 port that is only using 2 ports.&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;How safe/comfortable would you be if you used the same switch for DMZ and WAN traffic, but separate them by VLAN, and strict access trunks to a firewall?&lt;/P&gt;</description>
      <pubDate>Thu, 02 Dec 2021 00:34:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/2960x-wan-and-dmz-on-same-switch-separated-by-vlans/m-p/389527#M1084</guid>
      <dc:creator>Joshua2215</dc:creator>
      <dc:date>2021-12-02T00:34:56Z</dc:date>
    </item>
    <item>
      <title>Re: 2960X - WAN and DMZ on same switch separated by vlans?</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/2960x-wan-and-dmz-on-same-switch-separated-by-vlans/m-p/389539#M1086</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;It's always strongly recommended to use different layer 2/layer3 switches for WAN links and DMZ servers connectivity.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Suresh&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 06 Mar 2021 15:47:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/2960x-wan-and-dmz-on-same-switch-separated-by-vlans/m-p/389539#M1086</guid>
      <dc:creator>SureshReddyM</dc:creator>
      <dc:date>2021-03-06T15:47:57Z</dc:date>
    </item>
    <item>
      <title>Re: 2960X - WAN and DMZ on same switch separated by vlans?</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/2960x-wan-and-dmz-on-same-switch-separated-by-vlans/m-p/389596#M1087</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's not about how many ports are using or not using. It's about security. How much security you are providing for your server or servers in DMZ&amp;nbsp; and your wan interfaces are entry for all your outside (untrust ) traffic enter point ie inbound traffic. There are couple chances that attackers can initiate DOS or DDOS /flooding mechanism like syn and ip etc and also there is chance that ip spoofing or Mac spoofing or any one of above will down your network interface and it's tough to troubleshoot when even you get an issue or traffic issue. And also think about redudnacy solution all wan and DMZ are dependent on same switch also loop hole in design.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That's a reason I recommend to use two different or staked redudnat switches towards both links.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Suresh&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 07 Mar 2021 16:42:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/2960x-wan-and-dmz-on-same-switch-separated-by-vlans/m-p/389596#M1087</guid>
      <dc:creator>SureshReddyM</dc:creator>
      <dc:date>2021-03-07T16:42:36Z</dc:date>
    </item>
  </channel>
</rss>

