AP7 vqlan and microsegmentation Ethernet
-
Hello Firewalla, can you provide more information or clarity on how or when home run connections to a switch will be able to be included in a microsegmentation group? @Jonathan asked the same or similar question and it appears still not answered. You have provided very recent updates which clarify more about this potential issue: VqLAN: Firewalla Microsegmentation – Firewalla.
I'm sure I misinterpreted the full functionality of FW's microsegmentation as it applies to direct connections to a same switch. I thought all devices in a FW router AP7 infrastructure would be able to take advantage of this powerful opportunity.
It almost implies we need an AP7 with additional RJ45 ports to provide home runs into a more resilient ecosystem. I currently have a core switch which connects to each AP7 and will connect to each FW ceiling AP (CAP7?). My core switch is a managed Omada switch, home runs to my core switch come from a few PC's and other endpoint switches which connect to devices in a fringe area of my house (e.g. TV area connecting a TV and a Roku directly vs using Wi-Fi).
As this is really new information for myself, which makes sense. I am now rethinking about the FW switch surveys and the appropriate switch should have managed capabilities to allow for home run connection controls. Probably means fewer port 2.5 Gb switches so they can be used as end point switches vs a core switch application.
Maybe this post should be in the above referenced link: VqLAN: Firewalla Microsegmentation – Firewalla.
-
@firewalla - you mentioned that:
“ VqLAN microsegmentation only works with device traffic that is terminated inside the AP”What about VLANs that are terminated on Firewalla? In other words, I have a L3 managed switch but let Firewalla handle the routing (set next hop, default GW, to Firewalla) not the smart switch. Will VqLAN work in this scenario?
Please sign in to leave a comment.
Comments
9 comments