Skip to main content

06 · Corrected switch design

Same topology as 05, with the core split by traffic direction

Identical to 05 · Production topology in every other respect — only the core tier changes: one pair now owns north–south WAN traffic, the other owns east–west intranet traffic, joined by a routed link instead of a shared L2 stack. The production topology rebuilt on the rules from 01 · Separate the cores: a single gateway firewall HA pair owns all policy, and the switch tier splits into an internet edge pair and an intranet core pair. Racks stay one group, separated by VLAN.

North–SouthEast–WestAir-gap / at-riskPeer / HA linkFabric mesh Internet border · Inspection & edge LB · Partner circuitsidentical to 05SINGLE FIREWALL LAYER · ONE HA PAIRPalo Alto firewalls · HANORTH–SOUTH · WAN ZONE · HAEdge SW AactiveEdge SW BactiveEAST–WEST · LAN ZONE · HACore Switch AactiveCore Switch Bactiveair-gaprouted linkOther IDC · core pairSite-to-site · HA both endsONE RACK GROUP · TOR PAIRS DUAL-HOMED TO EDGE AND CORETOR A / BServer VLANs + Payment VLANTOR A / BServer VLANs + Payment VLANWorkload tier (identical to 05)

Single firewall layer

One HA pair owns all policy; NCCC and partner circuits terminate on the same pair; partner transit enters via the edge switches.

Core split

Edge pair owns north–south WAN, core pair owns east–west LAN, joined by a routed link (no shared L2 stack).

Inter-VLAN routing

Inter-VLAN traffic is routed by the firewall pair — one policy point for both north–south and payment.

:::note Payment VLAN Same rule as 05: payment servers sit on a separate VLAN in the same rack group; traffic is always routed through the firewall, never switched directly. :::