@stevenjwilliams83 wrote: I am not trying to do anything, I am just trying to understand it. So if my gateways exist on another device other than the PAN, why not run it in vwire between the switch and layer 3 device? Many ways to skin a cat, but trying to see what way others skin it. I think in a good majority of use cases the gateway is the firewall, in the cases where it's not then you're right vwire would also be an appropriate solution. I've only ever deployed vwire once, in a limited deployment, but it's my understanding there are some things you can't do in vwire. So if you're looking to implement a vwire deployment I would be sure all features you need/want are supported. (I think response pages via vwire for non-decrypted traffic isn't possible.)
... View more