This configuration allows a given link between the firewall and the Switch to be designated as the dedicated uplink set up to carry PortShield traffic corresponding to the connected firewall interface. The firewall and Switch ports are configured in trunk mode for the VLAN corresponding to the PortShield VLAN of the firewall interface.
This configuration can be used in deployments where a dedicated 1G link is needed for a particular firewall interface. Cases where this configuration is necessary:
The risk associated with such a configuration is using up interfaces on the firewall fairly soon.
In this example, there is no common uplink to carry the PortShield traffic for the rest of the firewall interfaces (excluding X0 and X5 for which dedicated links are set up).
For dedicated uplinks to work, the physical link must be connected before being configured.
The diagram, Dedicated Uplink Topology, shows a dedicated uplink setup of a firewall with a Switch. There are two dedicated uplinks in this scenario:
In addition, there are two dedicated uplinks:
Dedicated Uplink Topology
You can configure a dedicated uplink with or without setting up the common uplink to carry all PortShield traffic for the different firewall interfaces. In both cases, the common uplink is used to manage the Switch.
To configure a dedicated uplink topology without an common uplink
Once the Switch port is enabled, go to Switch Port Settings as described in Setting Up Ports. Set portshields to support dedicated uplinks. In this example, port 7 is portshielded to X5.