@Bruce Thanks for the reply. When I mention Management/Up link port, I am using port 48 on one of the WAN switch as management/up-link port, not a separate dedicated management Port. When I use port 48 on a switch as Management/Up-link port, I am not comfortable connecting it directly to Internet as there is not any protection available for the port and my understanding it will be listening as well - it will be prone to DoS attack etc. As you stated both design are OK, then I will prefer to connect the Management/Up link port to our LAN management network then provide Internet connection via FWs. As you have also mentioned, the drawback is if there are any issue with FW cluster, we will not be able to manage WAN switches or identify whether issue is with WAN switch stack or FW cluster.
... View more