On the attached, I have a bunch of servers trunking up to a Juniper 4100 SRX. The gateway addresses should reside within VLANs on the Juniper and all servers are should be forced up to the firewall. No server should be able to talk to another server without a rule in place. All these servers should sit within a Zone on Juniper. This will be via 2 interfaces to a couple of switches working in a pair. Are IRB interfaces the best way to do this with VLANs?
The rest of the network will connect into this Juniper, but I have read that you can't have a layer 3 zone talking to a layer 2 zone?
Now I am wondering how best to connect up these parts of the network? I was going to have a OSPF connection to the rest of the network but this means the 2 zones can't have rules between them which is needed.
Any help greatly appreciated?
Just to clarify, each switch has 2 links to the Juniper SRX