use a MS switch without a security appliance with dirty internet

TheAlchemist
Getting noticed

use a MS switch without a security appliance with dirty internet

As it is possible to create a network using just a switch without a security appliance, is it possible to feed that switch dirty internet and use it.

 

 

6 Replies 6
alemabrahao
Kind of a big deal
Kind of a big deal

Yes as long as the default route is your ISP's router.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
BlakeRichardson
Kind of a big deal
Kind of a big deal

It sounds incredibly insecure.....

TheAlchemist
Getting noticed

I have always setup with a Mx or a Z1 device but a layer3 MS switch is capable of running on its own in Meraki network. I could create a network in Meraki based on ONLY a switch. But, can I use it as a flat switch ? I guess not. And as @alemabrahao mentions, where can I setup the uplink info as I can normally do on an mx/z1 device.

Configure a layer 3 vlan interface with a public IP then assign any switchport that vlan as an access port - that is then your uplink port

Darren OConnor | doconnor@resalire.co.uk
https://www.linkedin.com/in/darrenoconnor/

I'm not an employee of Cisco/Meraki. My posts are based on Meraki best practice and what has worked for me in the field.
DarrenOC
Kind of a big deal
Kind of a big deal

I assume this switch is going to be isolated from the rest of your network and isn’t your production network?

 

As already mentioned this is a security risk.

Darren OConnor | doconnor@resalire.co.uk
https://www.linkedin.com/in/darrenoconnor/

I'm not an employee of Cisco/Meraki. My posts are based on Meraki best practice and what has worked for me in the field.

This is for any urgent case scenario where we are left with no choice and definitely for a temporary use case.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels