Cisco Firewall :: (6500 Or 7600) Maximum Virtual Interfaces (VLANs) (FWSM)

Nov 23, 2012

tell me for the FWSM (blade on 6500 or 7600) the maximum number of virtual interfaces (VLANs)

View 14 Replies


ADVERTISEMENT

Cisco Firewall :: 6500 Maximum Virtual Interfaces

Dec 10, 2006

How the FWSM (blade on 6500 or 7600) the maximum number of virtual interfaces (VLANs)

View 4 Replies View Related

Cisco LAN :: Management Interfaces On 7600 Switches And Its VLANs

Jul 19, 2012

I am using a Catalyst 7600.
 
I set up a VLAN interface (VLAN 3) with an IP-address and I can connect to it using telnet and log in to the switch as admin.I call this my management interface.
 
How come I manage to log into the management interface when the native VLAN is default 1? I thought the native VLAN determines which VLAN I need to log into to access the switch?
 
Can I make management interfaces of all the 48 ports if I want?

View 5 Replies View Related

Cisco Firewall :: 6500 - FWSM - Not Passing Traffic Through Firewall

May 3, 2011

We have 2 FWSM modules in each 6500 switches. 1st module is having 04 firewall vlan groups with 18 vlan interfaces in a single context firewall. All are working fine with no issues. Recently we create one more vlan on MFSC and add into the same firewall module. However newly created vlan inside the FW is not able to communicate with outside and also outside users not able to reach newly created subnet. But within the firewall zones (other interfaces) it can communicate. Once we did packet capture we noticed that its hitting firewall outside interface only and when we ping we got TTL expired error. we have default routes to outside and there's no any route inside as new segment is within the firewall (no any hop).
 
I guess there's no limitation on number of vlans that we can assign on one firewall eventhough there is a limitation for number of vlan-group which is 16 max (but we are within that limit).

View 2 Replies View Related

Cisco Firewall :: 6500 - FWSM And ACE S/W Compatibility

Aug 14, 2011

We have a pair of 6500s with Sup720 running 12.2(33)SXI3. Each has an ACE-20 (s/w A2(2.0)) and FWSM (s/w v3.2(15)). We have reached a limit on the number of rules we can configure on the FWSM, and have determined that we shall upgrade to 4.1(5), with ASDM to 6.2(2)F. A question has been raised regarding the s/w on the ACE-20 modules. Do we need to upgrade them as well?

View 2 Replies View Related

Cisco Firewall :: FWSM Reset With 6500

Feb 3, 2012

I have had a strange issue with a pair of FWSM's in 2 6500's, it seems there was a failover but both module's have been reset.
 
CAT1
Feb 03 17:08:46.525: %SNMP-5-MODULETRAP: Module 8 [Down] Trap Feb 03 17:08:46.522: SP: The PC in slot 8 is shutting down. Please wait ...Feb 03 17:09:01.525: SP: shutdown_pc_process:No response from module 8 Feb 03 17:09:11.382: %C6KPWR-SP-4-DISABLED: power to module in slot 8 set off (Reset) Feb 03 17:10:56.093: %DIAG-SP-6-RUN_MINIMUM: Module 8: Running Minimal Diagnostics...Feb 03 17:10:59.796: %SVCLC-5-FWVTPMODE: VTP
[Code]...

View 1 Replies View Related

Cisco Firewall :: 6500 - FWSM Linux

Dec 20, 2012

We run a 6500 with an FWSM with multiple security contexts as well as cascading contexts with a "shared V LAN" . There is a problem with regards to Linux machines and our shared network.

For example, we have three Linux machines in production, each in three separate V LAN's. For me to communicate to these boxes from one V LAN to another I must first ping the server. If I do not ping the server it will not bring up a connection like ssh or HTTP, etc. Below is the error I get from the FWSM that hosts the Linux server, but like I said once I ping the server the error goes away. We only have this problem with Linux machines, and it is a problem for all three of them. Is the FWSM having issues understanding something with all three Linux boxes? Below is the error I get at first, when I try to SSH from one V LAN to another V LAN with the Linux machine. 

6 Dec 21 2012 16:33:54 106015 10.255.12.109 22 10.255.1.30 63000
Deny TCP (no connection) from 10.255.12.109/22 to 10.255.1.30/63000 flags SYN ACK on interface inside.  
 
Below is what happens when I initiate a ping to the Linux Server and then ssh again. Notice it builds the connection with no problem after the ping. During the ping it builds the dynamic translation, and then when I ssh it builds the TCP connection. Do you know why this could be?

6 Dec 21 2012 16:35:08 305009 10.255.12.109 10.255.12.109
[Code]....

View 7 Replies View Related

Cisco Firewall :: FWSM 3.2 Can Not Show Sessions In Xlate Between Two Specific Vlans

Dec 23, 2012

I have FWSM running version 3.2(23) , configured with interface vlans , all having the same security level , except outside interface vlan which has security level 0 , also same-security-traffic permit inter-interface and same-security-traffic permit intra-interface are configured, my problem is when establishing sessions (I tried TCP only using ssh and telnet , in addition of ping ) from one specific vlan (172.16.1.0/28)  to other vlan (172.16.1.16/28) , I can not see the established sessions  in "show xlate debug" output ! although I can see these sessions from capture !  the two subnets are separate , two different /28.
 
I can see the session established from the remaining interface vlans with same security level toward  172.16.1.16/28 , my question is what is the exception with vlan having this subnet172.16.1.0/28, how it can reach other vlan with subnnet 172.16.1.16/28 without showing anything in xlate table ? do you thing it is bug ?

View 3 Replies View Related

Cisco Firewall :: 6500 - FWSM With Multiple Connections?

Aug 29, 2012

There is a 6500 switch with fwsm. We have extended 2 vlans from the ISP into the FWSM. Also there are atleast 10 other vlans for our internal network. We would like say half of the internal vlans to go out of the 1st ISP vlan and the remaining half from the 2nd ISP vlan. Is there a way we can do this in the FWSM?

View 2 Replies View Related

Cisco Firewall :: Fail Context From One FWSM Over To Other 6500

Oct 23, 2012

Firstly is this the right forum to post threads about FWSM's. We have 2 FWSM's in two seperate 6500 switches. There are a number of contexts on each FWSM.I want to fail a context from one FWSM over to the other 6500 and FWSM. Can you tell me how I can do that? Do I need to do it in the admin context and do I need to do it on the admin context of each 6500?

View 7 Replies View Related

Cisco Firewall :: 6500 - Introducing ASA Into Setup Instead Of Using FWSM

Jan 3, 2013

We are thinking of introducing ASA's into our setup instead of using FWSM for our firewalls with our 6500. Currently we use multiple contexts with the FWSM, as we provide hosting services for multiple clients and want them behidn their own firewall. My question is how can we make this happen with an ASA. Since with the FWSM we use the backplane of the 6500 and SVI's for all interfaces between them. For example if we have 20 clients what will be the ideal setup for us to use with an ASA. If we can infact use mutiple contexts how can we? Is there a way we can maybe bundle all the ports in the ASA into the 6500 as a layer two trunk port and continue to use SVIs to manage all the clients.

View 3 Replies View Related

Cisco Firewall :: 6500 Admin Context On FWSM

Dec 3, 2012

I have just joined a networks team and will be working on two fwsm versions 4.0(8) in two 6500 routers. Now the fwsms seem to be virtualised with multiple contexts. The server team want a new context setup for a group of servers behind a vlan. [code]
 
This context just seems to have  two Vlans and a BVI interface. What is the function of this context and why we have 2 admin contexts?
 
Also another important question is on which 6500 do I create the new context? Is the admin context active on one 6500 just like other contexts and will sync across or do I have to create the new context on both 6500s.

View 7 Replies View Related

Cisco Firewall :: 6500 FWSM Vlan Interface

Jan 29, 2012

Is it possible for me to create 2 vlan interfaces on the 6500 and have them both in the same subnet?
 
For a specific customer requirement I would like to have a vlan interface on the 6500 as default gateway, sat in it's own vrf, and then route all traffic inbound and outbound to this vlan through the FWSM interface, preferably in the same subnet. I don't think this will be possible so just looking for confirmation either way.
 
As I will be running EIGRP between a pair of central 6500's and 2 remote offices it will make things much easier for me advertise the connected FWSM interfaces in to EIGRP for access in/out of all my VRF'd subnets. If I need another subnet for each VRF FWSM next hop then I'll have to reditribute a list of statics which I don't really want to do.
 
The reason I am not just using the FWSM as gateway is because I need to run HSRP across 3 different devices (another 6500 in a second suite), and failover FWSM will only give me 1 level of redundancy for those gateways.

View 3 Replies View Related

Cisco Firewall :: Shutting Down And Removing FWSM From A Production 6500

Feb 24, 2011

I need to remove FWSM from a prodcution 6509.  This FWSM is a standby.  What's the best way to remove without powering down the switch or impacting antyhing? 

View 3 Replies View Related

Cisco Firewall :: 6500 - Passive FTP Through 2 FWSM Contexts Via VRF Instance

Mar 26, 2012

I'm having problems getting FTP to work through two FWSM virtual contexts which are connected via a vrf. All this is configured on a 6500 switch with the FWSM running 3.1(4)
 
CLIENT-----CONTEXT_1-------VRF------CONTEXT_2--------FTP_SERVER
 
At the moment we can make the control connection but when we issue commands the connection times out.
 
Looking at the logs we can see the initial connection made to the server on port 21 from the client, this is also seen on the second firewall context (nearest the FTP server). The data channel is then seen on the first context, made using high src & dst port numbers and initiated from the client, successfully passing the ACL/Inspection, then on the second context we see the connection being denied by the incoming ACL on the second contexts interface connected to the VRF instance.
 
The rules are identical on the contexts and have been made by copying and paste the rule using CSM, we are using the predefined service group 'FTP-Group' which contains both tcp 20 & 21. FTP inspection is at default on both contexts.
 
We have tested with Win XP (capable of Active FTP only) & Firefox 3.6.12 which is the connections we are seeing in the logs trying to do Passive FTP.
 
Is this a problem with teh contexts randomizing sequence numbers or TCP Normalization? Or do we just have a problem with the Inspection engine on one of the contexts (I would have expected to see this on both contexts if it was a bug).

View 1 Replies View Related

Cisco Firewall :: 6500 / Static NATS For FWSM Contexts?

Jun 28, 2011

I am just designing a solution where a FWSM consists of 2 contexts initially and has a shared outside interface pointing to the 6500 switch. There are 3 subnets connected to each of the FWSM contexts. So if anyone wants to access these 6 subnets then a route would be needed pointing to the interface vlan of the shared interface on the switch. But that would not be enough to access the subnets.. I am sure we have to define static NATS to point them to the right context where these subnets reside.
 
The FWSM is running version 3.x code So say 1.1.1.0(shared), 10.10.0.0(inside1), 10.20.0.0(inside2) and 10.30.0.0(inside3) reside in Context 1 and 1.1.1.0(shared), 20.10.0.0(dmz1), 20.20.0.0(dmz2) and 20.30.0.0(dmz3) reside in Context 2 in each of the context we would have to make three static NATS
 
static(inside1,shared) 10.10.0.0 10.10.0.0 netmask 255.255.255.0
static(inside2,shared) 10.20.0.0 10.20.0.0 netmask 255.255.255.0
static(inside3,shared) 10.30.0.0 10.30.0.0 netmask 255.255.255.0
 
The same would go for context 2 as well
 
static(dmz1,shared) 20.10.0.0 20.10.0.0 netmask 255.255.255.0
static(dmz2,shared) 20.20.0.0 20.20.0.0 netmask 255.255.255.0
static(dmz3,shared) 20.30.0.0 20.30.0.0 netmask 255.255.255.0
 
By creating these NAT statements, would the outside users be able to access the subnets residing in the context?

View 1 Replies View Related

Cisco Firewall :: FWSM On 6500 - Read Only User Addition?

Mar 20, 2011

I have a customer that has a FWSM on a 6500, I want to create a read only account for them, i believe user privelage of lvl_3 When I log into the firewall it prompts me for a password straight away.
 
Is there a way that i can create a login that when it prompts me for a password, I can have a password setup to put into that prompt to get a certain level of access, instead of the standard lvl_15 access

View 9 Replies View Related

Cisco Firewall :: 6500 FWSM Module Upgrade Recommendation

Aug 24, 2011

I'm looking at upgrading our FWSM modules in our 6500's. They're the WS-SVC-FWM-1 modules.
 
We're running on version 3.2(12) at the moment and I'm looking to jump up to 4. Any recommendations around whether I should to go to 4.1(6) or 4.0(16)? There aren't any features in particular that I would need in 4.1 but want a good stable base to sit on for 12 months until I look at this exercise all over again.

View 5 Replies View Related

Cisco Firewall :: WCCP Support On FWSM Running 6500

Mar 10, 2011

What the support for WCCP on a FWSM running 4.0(7) is like, if there is any at all ?
 
I've read that the earliest PIX release that supports WCCP was 7.2(1) but I'm not sure how FWSM 4.0(7) aligns with the PIX versions.The only doc's i can find refrencing WCCP on a 6500 with FWSM is in the 6500 12.2 IOS guide.

View 1 Replies View Related

Cisco Firewall :: 6500 FWSM Active / Standby In VSS Mode

May 10, 2012

i do have two 6500 in VSS mode , and one FWSM module on each 6500, i want to configure these modules as Active/Standby, how do i start , should i  follow this (not in VSS mode): url..

View 1 Replies View Related

Cisco Firewall :: 6500 Can Shutdown Vlan1 On Switch And Still Communicate With FWSM

Jun 17, 2012

It is my understanding that the FWSM for the 6500 series switches uses a 6 port Etherchannel on the backplane to communicate with the 6500 series switch.Can you shutdown vlan1 on the switch and still communicate with the FWSM? I was under the impression that you could not (although I am looking at a config with it shutdown)

View 1 Replies View Related

Cisco Firewall :: FWSM On 6500 TCP Connection After Crash On Primary Network

Aug 6, 2012

We are running an FWSM on a 6509 with a SUP720. Firmware 3.2(18), in MultiContext Routed Mode, with shared MSFC.Everything runs fine on this baby most of them time, however occasionally without warning and with no specific pattern the Primary node will fail (as in completely stop responding) and the secondary will takover as active. Two get the primary up agian, I reset the hw-module and then no failover active on the secondary to return the primary as active. However, after this event, I start to experience strange issues with connectivity. Certain TCP src dst combinations will just not work.

View 1 Replies View Related

Cisco Firewall :: 6500 - Applying Multiple FWSM Rules Changes In A Batch

Jun 26, 2011

I'm using ASDM 6.2 with a FWSM on a 6500.
 
At the moment everytime I want to make a change to firewall rules I click apply and the rules are applied Immediately. I have to make multiple changes during the working day which I don't like to do.
 
What I would like to do is make changes during the day but not apply them until out of hours (some sort of batch mode). Like I can do in my check point firewalls.

View 1 Replies View Related

Cisco Firewall :: 6500 - Unable To Ping When Use Routed Mode In Fwsm

Feb 17, 2012

I have 2 modules of FWSM in 6500 switch (failover). I need 5 context. When I use in routed mode (like in the picture) , I cannot ping the servers behind the firewall. (I have ping to FW context) In transparent mode, it is not happening.

View 1 Replies View Related

Cisco Firewall :: ASA5520 / 3560 - VLANs And Sub Interfaces

Aug 20, 2012

ASA's G0/2 interface is connected to G0/1 interface of a 3560G switch in DMZ, below is the config and diagram
 
Switch Config
int g0/1
switchport mode trunk
switchport trunk encapsulation dot1q
int vlan 1
ip add 192.168.0.100 255.255.255.0
 
We are running out of IPs in 192.168.0.X network and planning on creating sub interfaces on the ASA and trunk it to the switch so that we can have multiple V LANs in DMZ. Tried the below config in LAB but that didn't work, can you have a look at it and let me know if I miss anything. No change on the switch config since G0/1 is already a trunk port.
 
ASA Config
interface GigabitEthernet0/2
description Trunk to DMZ networks
no nameif dmz
[code]...
 
If I change the V LAN on the switch from 1 to a different V LAN, say V LAN 50 for example, and configure the ASA accordingly its working fine.

View 5 Replies View Related

Cisco Firewall :: Cat 6500 FWSM System Space Does Not Replicate Part Of Configuration

Jun 11, 2012

I have FWSM failover pair, Active/Active configuration, admin and another 4 context, few context active on first FWSM, other on second FWSM.I needed to add  VLANs 51 and 52 to FWSMI created VLANs on both Cat6500, created firewall vlan-group 3 a and put "firewall module1 vlan-group 3" on both cat6500Then I log in in system space on primary FWSM and created interface VLAN.Created VLANs automatically occured in system space on  Secondary FWSM.Then I wanted allocate VLAN 51 and 52 to context XY, so I went to part of configuration for context XY and "allocate-interface Vlan51" and  "allocate-interface Vlan52".

View 1 Replies View Related

Cisco Firewall :: Configure ASA To Send All Traffic From (3) VLans To Interfaces That Connects To 2960?

Apr 18, 2013

I have a an ASA 5520 connected to a Layer 3 (3750) switch (Inside) and a connection to a 2960 switch (Outside) to get to the internet. . I have created vlan interfaces on the 3750 switch and enabled ip routing on the switch to enable the vlans to communicate with each other.
 
Vlan Interfaces on the switch:
Vlan 100 172.17.1
Vlan 200 172.18.1
Vlan 300 192.168.3.1 
 
I want the devices connected to the 3 vlans to be able to pass through the firewall and get out to the internet.I have connected the ASA to the 3750 by routed interfaces (10.10.10.1) --------- (10.10.10.2) and they are able to ping each other.I have also put a default route on the 3750 sending all traffic from the switch to the ASA inside interface (10.10.10.1)The issue that i am having is that the ASA also connects to a 2960 which has a connection to the Internet, and they are handing off an ethernet connection from the 2960 that sits in VLAN 55 (Vlan 55 is the Internet accessible vlan).How do I configure my ASA to send all traffic from my (3) vlans to the interfaces that connects to the 2960 switch?

View 21 Replies View Related

Cisco Firewall :: Firewall Vlans On Catalyst 6500 By Using ASA

Aug 9, 2012

How to secure vlans on Catalyst 6500 by using Cisco ASA Firewalls?There are no free modules on Catalyst 6500 to install a FWSM module.What is the best configuration to secure vlans (~80 vlans) by using cisco ASA firewalls (context, hairpining...)?

View 1 Replies View Related

Cisco :: FWSM Communication Between Same Security Level Interfaces

Sep 21, 2012

I have 2 dmz interfaces(dmz1 and dmz2) with security level 50. I am able to ping the hosts on dmz2 from dmz1. I am running a service on a dmz2 host on port 82 but i am not able to access that service from dmz1. Also, i have an inside interface at security lever 99 which is able to access that service.

Also, i have defined the following command to allow same security level communication.

same-security-traffic permit inter-interface

View 2 Replies View Related

Cisco WAN :: 3750X - Maximum Interfaces With Pim?

Jun 5, 2013

on 3750X how many interfaces can be configured with PIM activated on ?

View 2 Replies View Related

Cisco Switching/Routing :: 6509 FWSM VLANs Do Not Show Up

Feb 7, 2012

Configuring FWSM in a 6509.  When I set "firewall vlan-group 40  40-42,251", it results in: "No more than one svi is allowed. Command rejected.". 
 
I had "firewall multiple-vlan-interfaces" set for a previous use of this module, but took that off with the "no" command.  Suspect that is the issue, but do not see how to resolve.  Seems similar to bug CSCsr48563, but I am at the fixed code for that bug.

View 1 Replies View Related

Cisco WAN :: Used DDR Memory On DFC On Linecards For 7600 / Catalyst 6500

Dec 12, 2011

What is used DDR memory on DFC on linecards for Cisco 7600 or Catalyst6500? I thought that DFC has copy of TCAMs from PFC. That PFC only has TCAMs, and it doesn't have DRAM on itself?
 
I've been said that if I have full BGP table in memory on supervisor on 6500 (that should be DRAM on RP on MSFC) that I also need 1GB additional memory on DFC on linecards? Is this true? But that should implied that DFC also has copy from MSFC not only from PFC, is this correct?

View 5 Replies View Related

Cisco WAN :: 7600 / 6500 / ASR9K - Route Processor Information

Feb 19, 2012

I am very new to high end Cisco devices.(like 7600/6500 or ASR9K).
 
Why do we log in on RP. What actions we can perform after logging-on RP (route processor) or Why they are required ? Cant we  make those by normal router mode (router#) .

View 2 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved