- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Best Practices for Using Meraki Firewalls as Data Center Firewalls
Hello,
I am considering using two Meraki firewalls (configured in High Availability mode) as data center firewalls to manage traffic between servers and other VLANs.
I would like to know:
- Is it recommended to use Meraki firewalls in this role within a data center environment?
- What are the best practices for configuring Meraki firewalls for this use case?
- Are there any specific considerations or limitations I should keep in mind when implementing them in such a setup?
Your insights and recommendations would be greatly appreciated!
Thank you!
- Labels:
-
Firewall
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
As always…it depends!
- budget
- overall solution design
- Firewalling requirements within the DC
- what issues or business requirements are you looking to address by implementing DC firewalls
https://www.linkedin.com/in/darrenoconnor/
I'm not an employee of Cisco/Meraki. My posts are based on Meraki best practice and what has worked for me in the field.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I have a client with a flat network who wants to deploy a firewall in front of the servers without changing any IP addresses or configurations. He also wants to enable syslog on the firewall for traffic monitoring and analysis. I want to configure the firewall as a bridge (Layer 2).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If you are wanting Syslog check out this documentation and make sure that it covers what you are wanting to capture.
Meraki use to offer free trials of equipment (not sure if they still do or not) so I would reach out to your Cisco rep and see if you can get something to have a play with.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If I understand, all the servers are in a single subnet and VLAN, and the client wants protection from the Internet.
The MX will be fine for this simple use case.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I want to protect the servers from the user. This is a requirement from a state security institution to have a firewall placed before the servers, not the internet. I also have an MX67 as an edge device.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
As much as I love Meraki and the fact that I don't know how large your environnement is, I wouldn't use a Meraki MX for that.
