Protect the link between the firewall and the switch

Elgen07
Elgen07 Posts: 8 image  Freshman Member
First Comment Fourth Anniversary

Hi

I’m using MAC authentication on a GS1920-24 switch to prevent unauthorized devices from connecting to it. However, I can’t use MAC authentication on the uplink to the firewall. How can I ensure that only the firewall can connect to the switch, and only the switch can connect to the firewall? The firewall is a USG FLEX 100.

Best regards,Olav

All Replies

  • PeterUK
    PeterUK Posts: 4,166 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    edited October 26

    There is no way I see you can do this you could ACL the source MAC of the FLEX 100 LAN gateway or/and add all the destination MAC clients. Or to make it so that no untag device can connect to the FLEX 100 by using a VLAN.

    But the idea is no one would have access to the uplink.

    I guess what you want is to encrypt the the link? Interesting idea such that packets are encrypted and can only be decrypted by matching key.

  • Zyxel_Melen
    Zyxel_Melen Posts: 4,019 image  Guru Member
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @Elgen07

    Normally, the firewall and core switch should not be easy to touch. May I know where did your place?

    For the function to prevent unauthorized devices, you can enable MAC authentication on the switch only if no other device is connected to the firewall on the same interface. On the firewall, there is no option to achieve it.

    Zyxel Melen


  • Elgen07
    Elgen07 Posts: 8 image  Freshman Member
    First Comment Fourth Anniversary

    Hi,

    Thanks for your reply — you pretty much confirmed what I feared. However, perhaps it would be a good idea to secure the link between the firewall and the switch.

    Best regards,Elgen

  • PeterUK
    PeterUK Posts: 4,166 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    edited 7:29PM

    Or you can get another USG and do a VTI so that where the switch is you have a short link to this other USG then VTI to the main USG