Hi All,
Got an interesting one here. The requirement is the following -
HP switches connected to the firewall via a trunk with the L3 interfaces of the "production" VLAN's on the firewall. So devices on the HP switches on the specific VLAN's will use the firewall as the default gateway and various rules applied before traffic being allowed / disallowed to other L3 interfaces.
Example:
Production VLAN's -
VLAN10 - 192.168.1.0/24
VLAN20 - 192.168.2.0/24
Trunk99 connected to checkpoint from HP switch with VLAN10,20.
Layer 3 interface on Checkpoint for the production VLAN's of .1 for each VLAN.
Enterprise VLAN's -
VLAN30 - 172.16.1.0/24
VLAN40 - 172.16.2.0/24
Trunk 1 connected to checkpoint from HP switch with VLAN30,40
Layer interface on HP switch for the production VLAN's of .1 for each VLAN.
With appropriate routing and firewall rules the traffic flows between the two environments.
NOW... I want to add a completely new switch environment, which is separate from the HP. So let's say it's Cisco. Can I add another trunk to the checkpoint firewall connected to a Cisco switch with VLAN10,20 using the same ranges - effectively using the firewall as the router if you like?