r/sysadmin • u/drc997 • 4d ago
Internal firewall Question
Hi, we have a simple setup hosted in a data center. Firewall, switch, virtual machines. The VM's are mostly web servers and database servers. We are looking to separate the two into a production network and data network and firewall the two apart. I know I can do this with VLAN's and use the main firewall to control access to the data network but it feels like if the edge firewall has access to the data network it defeats the purpose of having them on a separate network. Are there any recommendations for a software firewall I can create as a VM that are free or cheap that are not the standard pfsense and such? The main firewalls are watchguards and I know I can get a watchguard VM but the cost seems high for what it is going to do? What is typically used in the enterprise as a simple internal firewall?
-1
u/drc997 4d ago
I'm sure most of the companies that were breached in the last decade had half a brain and thought they were properly secured also. While entirely possible, routing access to sensitive data using the edge firewall doesn't seem like a smart option. Sorry, sticking to my guns here and going to find a better way.