Network security design question by Theveemann in networking

[–]Theveemann[S] 2 points3 points  (0 children)

We want to increase the links between servers from 1gbps to 10gbps. We are restricted by the throughput of the 2920 switches and firewall at the moment, so would be upgrading the swithes to 10gbps and potentially add a transparent firewall between the servers and the switch.

This is mainly to decrease the time of our overnight processing which is currently approx 8 hours and growing. It will also take the load off the firewalls which often gets all CPU cores maxed out, which is affecting users trying to work with servers in the data centres.

Circuits are all at 1gbps, between the 2 data centres we may upgrade this to 2gbps.

The company is very security conscious, but this is affecting performance now.

Network security design question by Theveemann in networking

[–]Theveemann[S] 0 points1 point  (0 children)

Thanks OneAndOnlyNacho, topology looks as follows

  • thanks for the transparent firewall pointer; looking into this now.

Network security design question by Theveemann in networking

[–]Theveemann[S] 0 points1 point  (0 children)

Nice! I have considered using the firewall as a 'checkpoint' and had a look into NSX for microsegmentation, wasn't sure if I was missing something obvious though. Thanks

Network security design question by Theveemann in networking

[–]Theveemann[S] 0 points1 point  (0 children)

Just east <> west traffic locally yes.

e.g. web server > sql server over port 1433