Hi,
I am new here but I do have a solution for your request.
Switch has the following VLANS and SVI's
VLAN 700: 172.16.70.254 255.255.255.0
VLAN 710: 172.16.71.254 255.255.255.0
VLAN 800: 172.16.80.254 255.255.255.0
Imagine you have a Cisco ASA firewall -
!
route outside 0.0.0.0 0.0.0.0 192.168.1.254
route inside 172.16.70.0 255.255.255.0 10.100.100.2
route inside 172.16.71.0 255.255.255.0 10.100.100.2
route inside 172.16.80.0 255.255.255.0 10.100.100.2
!
The route inside command tells the Firewall how to get to the appropriate vlans and the conduit or door to those respective subnets. Already the Firewall knows of the Switch's IP 10.100.100.2 and can ping to it. It does not know about the VLANS and the associated subnets and so you tell the firewall how to route traffic to them using the 10.100.100.2 (Switch's IP) to the appropriate VLANS.
On Switchip route 0.0.0.0 0.0.0.0 10.100.100.1 (IP Address of Firewall)
ip routing
Hope this helps you. The secret is getting the firewall to know who to pass packets to should there be any.