About This Architecture
Enterprise campus network using three-tier hierarchy with Palo Alto firewalls segmenting untrust, DMZ, and trust zones across H3C core switches in IRF stack and L3 aggregation layer with VRRP redundancy. Traffic flows from ISP through the firewall to web servers in VLAN 20, database servers in VLAN 21, and core infrastructure, with L2 access switches distributing to office PCs and wireless APs. This architecture delivers high availability through IRF master-slave core pairing and VRRP-based aggregation failover, eliminating single points of failure. Fork this diagram on Diagrams.so to customize VLANs, add additional access switches, or integrate OCI hybrid networking components. The design supports enterprise security policies by enforcing zone-based firewall rules while maintaining sub-millisecond convergence times via IRF and VRRP protocols.