04-03-2022 05:57 PM
Hi All,
We have a HA fw 3220 in our environment and our partner want to access some of our resources. They propose a PA-440 fw + small 12-port-Cisco 3560 in between the two sites by dark fiber.
Just wonder if you can setup FWs back to back instead of having a switch in between ie a extra point of failure?
is the Gateway going to be the switch or the FW440 behind it?
Any suggestion are much appreciated.
Thanks
QL
04-10-2022 05:06 PM
04-10-2022 07:54 PM
You can control the access in your end Firewall 3220.
Your partner network have dedicated fiber line till your network right. Then just create a VLAN in PA3220 assign it to security zone for ACL rule creation and extend it to your partner network switch.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!