Hi All,
If your ISP only gives you 1 hand off port ie SFP to serve a HA firewall pair is it bad practice to connect this into a Core switch as a L2 vlan?
The core switch MS250 also serves as LAN switch.
I have seen this done before and the MS250 has the correct amount of SFP ports i need eg
ISP >> MS250 (L2 VLAN) >> FW1 L2 VLAN WAN1 >> FW1 L3 VLAN LAN1 >>> MS250 L3 Vlan (LAN) >>>> Clients
ISP >> MS250 (L2 VLAN) >> FW2 L2 VLAN WAN 1 >> FW2 L3 VLAN LAN1 >>> MS250 L3 Vlan (LAN) >>>> Clients
Or is it better practice getting a WAN breakout switch to separate everything.
This is purely to save costs rather than having to but an extra pair of switches (MS120) where most of the ports will be sitting idle.
Thanks