I need some feedback on a network setup...
-
We have landed a new client thats a big mess from the earlier vendors.
Their LAN is segregated IP wise but not in any other way.
Everybody has access to everything on LAN, printer, cameras, servers you name it.
Its a big factory with multiple small networks racks with HPE switches currently not running any vlans at all.
The first thought is to isolate the servers on their own physical LAN. They are currently running ASA and I would like to switch to PfSense at the site.
And then NAT traffic from LAN to LAN_SERVER and vice versa.
Any thoughts?
-
@cool_corona said in I need some feedback on a network setup...:
And then NAT traffic from LAN to LAN_SERVER and vice versa.
Why would you nat between local segments?
-
@johnpoz They need access and DNS from the DC running on LAN_SERVER subnet
-
@cool_corona ok, again why would you nat? Those would just be firewall rules allow whatever you want between your network segments.
You have say 192.168.1/24 as lan, and 192.168.2/24 as your lan_server networks - why would you have to nat between those?
-
@johnpoz I wouldnt. Sorry. I misunderstood you :)