DMZ Default route for servers
Hi all,
I'm changing some things on my network. Currently (in summary) I have a DMZ with two Fortigate and one switch. The servers and the firewalls connect to the switch.
Each server has 2 static routes
1º)Default route --> IP address of the external fortigate.
2º)Route to reach internal private addresses -->Internal fortigate.
I'm thinking about configure the servers with just one default route for the switch that connects them. This switch, sends traffic to external or internal firewall and Doesn't route any traffic between DMZ network and other networks.
Server-->Switch-->Firewall Internal / Firewall External.
If I use a firewall as default gateway for servers, some times the traffic will have more hops than I want. Example
Traffic from server DMZ, to server Datacenter:
-ServerDMZ-->switch(layer 2)-->firewall external-->Switch another time-->Firewall internal.
What do you think about using a single default route to layer3 switch, that interconnects everything and it doesn't route between DMZ and other networks. It only sends traffic to internal or external firewall. It's an acceptable design to a DMZ in your opinion?
Thanks
