Cisco Firewall :: 6513 - FWSM Multiple Security Zones On Single Context

Nov 7, 2012

My corporate internal network is currently fire walled by an FWSM module on a 6513 switch.  We have each security zone (we have eight) assigned to a FWSM context and have ACLs set up between the contexts and the enterprise LAN/WAN.  Is it possible to support fire walling between these zones within a single security context?  The reason I am asking is that we would like to purchase a second FWSM for use as a standby, but do not want to cough up the ~ $12K for the context license.  We will ultimately be transitioning to ASAs for internal security, so do not want to spend more than we need to.

View 3 Replies


ADVERTISEMENT

Cisco Firewall :: 6513 Switch - Multicast Inside A Single VLAN In FWSM

Dec 6, 2009

I am trying to make the multicast working between few hosts inside a single vlan. Host are running mysql cluster and Multicast is used to send master/slave status  information to the IP 228.10.10.10 on port 45566.The vlan is  defined in FWSM and the host are connected via the core-switch(6513). (hosts-->core-sws--->fwsm)I have tried searching the documentation, but couldn't find specific info to enable multicast between hosts residing in same vlan. FWSM is running code 3.1(4). since the hosts are residing in the same vlan, I am thinking of applying the <multicast-routing> just for that SVI in FWSM.

View 6 Replies View Related

Cisco Firewall :: 6509 / Configure VPN In FWSM (4.0.4) Multiple Context?

Jan 8, 2012

i have 6509+FWSM(4.0.4)  now i wanna use stite to stite  and ez vpn in the fwsm (multiple context) multiple context mode in fwsm support ipsec vpn?

View 2 Replies View Related

Cisco Firewall :: 5550 Migrate From Multiple Context To Single

Aug 12, 2012

I have a Failover pair of ASA5550's running ASDM 6.2(5) and ASA 8.2(2).  Originally they were setup with 2 context's and an admin context but one of the contexts has now been removed.  I would like to now migrate to single mode before I go about patching them to the latest software.

View 4 Replies View Related

Cisco Firewall :: ASA 5550 - Migrate From Multiple Context To Single

Jun 13, 2012

I have a Fail over pair of ASA5550's running ASDM 6.2(5) and ASA 8.2(2).  Originally they were setup with 2 context's and an admin context but one of the contexts has now been removed.  I would like to now migrate to single mode before I go about patching them to the latest software. 

View 2 Replies View Related

Cisco WAN :: Security Zones With Multiple Inside NAT Interfaces 2901

Jan 14, 2012

I am having big problems trying to get what should be a rather simple configuration to work.I have a Cisco 2901 Router and have setup Zone Based Firewall on this.Traffic from the 192.168.223.x network does not pass through to the 192.168.1.x network.my traffic appears to disappear down the big bucket...Interesting I can ping machine on 192.168.223.0/24 network from the 192.168.1.0/24,So the static routes setup on the router on the 192.168.1.0/24 appear to be routing ok.

View 4 Replies View Related

Cisco Firewall :: ASA 7.2 Adding A Context In A Multiple Context Environment

Jul 1, 2012

On my production environment I have a firewall with already two contexts defined (15% of CPU used) and I want to add a new one.
 
This context is going to use the same interfaces as the others contexts. When I will enable the context, can I have some sort of repercussion on these two context ?

View 3 Replies View Related

Cisco Firewall :: ASA 8.4 In Multiple Context Mode With Different Amounts Of Context

Jan 13, 2013

I have two ASA 5510 in an Active/Active failover configuration; On the first ASA I have a license for five security contexts, on the second one I have the default two. On the pair I configured seven security contexts and everything works as expected; so far so good. Let's suppose now that the first ASA (the one with the license for 5 contexts) goes up in smoke; all the contexts migrate to the surviving firewall and life is still good. But what happens if, for some reason, I need to reboot the second ASA before the first one is repaired? My guess is that it will come up with just its own license for two contexts and that I will not be able to operate all my virtual firewalls.

View 2 Replies View Related

Cisco Firewall :: Fail Context From One FWSM Over To Other 6500

Oct 23, 2012

Firstly is this the right forum to post threads about FWSM's. We have 2 FWSM's in two seperate 6500 switches. There are a number of contexts on each FWSM.I want to fail a context from one FWSM over to the other 6500 and FWSM. Can you tell me how I can do that? Do I need to do it in the admin context and do I need to do it on the admin context of each 6500?

View 7 Replies View Related

Cisco Firewall :: 6500 Admin Context On FWSM

Dec 3, 2012

I have just joined a networks team and will be working on two fwsm versions 4.0(8) in two 6500 routers. Now the fwsms seem to be virtualised with multiple contexts. The server team want a new context setup for a group of servers behind a vlan. [code]
 
This context just seems to have  two Vlans and a BVI interface. What is the function of this context and why we have 2 admin contexts?
 
Also another important question is on which 6500 do I create the new context? Is the admin context active on one 6500 just like other contexts and will sync across or do I have to create the new context on both 6500s.

View 7 Replies View Related

Cisco Firewall :: Moving IDSM-2 And FWSM From 7613 To 6513?

Feb 5, 2013

I need your opinion regarding moving of IDSM -2 and FWSM Module from 7613 to 6513 chassis.Currently these two modules are in 7613 and we are not using either of them now we have to configure them in 6513 chassis. As you can see from the figure that traffic of all 3 core router i.e 7613 go to 6513 - to proxy ISA 2004 - 6513 - to Internet.
 
There are also some network attached with 6513 and we want to move both of modules to 6513 so that NetworkA/B/C/D/E which are attached to 6513 can also be configured for FWSM and IDSM -2.
 
I have a query regarding this migration:Do we need license for these two modules again for 6513 chassis?

View 2 Replies View Related

Cisco Firewall :: 6513 / All Traffic Move Via FWSM (Transparent Mode)

Apr 18, 2013

As I am planning to deploy FWSM Module in 6513 chassis and need your valuable comments regarding the strategy that I create for this deployment.Initially (Without FWSM Deployment) all internal traffic moves in this manner.
 
7613(G9/5) --> 6513(G10/4) --> ISA (Internal Int.) [NATing] (ISA External Int.) -->
6513(G9/45){This is L2 port in VLAN 164} --> VLAN 164(SVI Int,IP:192.168.40.20) -->
(G9/44){This is L2 port in VLAN 164}--> ASR 1002 -->Router -->Internet.
 
As you can see from the Image that I am planning to deploy FWSM in transparent mode in between VLAN 164(SVI Int,IP:192.168.40.20) -[FWSM here]->(G9/44){This is L2 port in VLAN 120}By putting Inside interface of FWSM in VLAN 164 and create a new VLAN  on 6513 i.e VLAN 120 and put G9/44 in it.know will this configuration will work regarding the passing of traffic through FWSM ? what improvement I have to made in this design. You can check the attached diagram.

View 3 Replies View Related

Cisco Firewall :: Cannot Access FWSM Via Session Command In 6513 (VSS Enabled)

Apr 24, 2012

Today i received FWSM from cisco (RMA), I need to configure it as standby unit for existing FWSM active/standby setup.
 
IOS on RMAed FWSM is 2.3.4 and  cisco VSS supports FWSM IOS 4.0.4 and later.My issue is, I cannot access FWSM (IOS 2.3.4) via session command from cisco 6513 but could successfully consoled it without any problem. I have reloaded it twice and also tried to disable and enable power on it.
 
VSS#sh module switch 2
 Switch Number:     2   Role:  Virtual Switch Standby
Mod Ports Card Type                              Model              Serial No.
--- ----- -------------------------------------- ------------------ -----------
   2    6  Firewall Module                        WS-SVC-FWM-1  -----------

[code]....

why I cannot access FWSM through session command ?Whether this is because of older IOS ? If yes then how to upgrade its IOS ?Is it possible to upgrade IOS via FWSM console ? if yes, Do i need to test on different slot ? 

View 2 Replies View Related

Cisco Firewall :: 6513 FWSM Coming Up Without Full Config After A Reboot

Oct 29, 2012

We have a customer who has 4 x 'WS-SVC-FWM-1' modules installed within 2 x 6513 chassis. The FWSMs are all running version 3.1(16) with failover group 1 and 2 enabled.After a few recent planned and un-planned power outages the FWSMs have come up without a full configuration. Is this a common fault? If so it there any kind of workaround that can be implemented?

View 5 Replies View Related

Cisco Firewall :: ASA 5585 Multiple Context Licensing

Apr 27, 2011

I am looking to deploy a cloud/borderless network solution and cannot get my head around how the licenses (AnyConnect Mobile and essentials) will be applied in a multiple context deployment. Any correct documentation.

View 1 Replies View Related

Cisco Firewall :: SSLVPN 9.0 / Web Vpn In Multiple Context Mode?

Mar 11, 2013

We already know that ASA 9.0 supports site-to-site VPN in multiple context mode. But remote access VPN isn't supported. Obviously, SSL-VPN is a very important feature for most multi-tenant deployment scenarios where each context acts as a border firewall towards the Internet for each tenant. The alternative to terminate all tenant remote-access VPNs in one context means that each tenant would have to be routable from the ASA, which of course isn't a reasonable requirement in most cases.
 
So, what I'd like to do is to deploy an ASA cluster, and provide remote access VPNs for each tenant, where the connectivity for each remote access group can be addressed with whatever IP address space, and that goes into it's own VRF in the back-end.
 
As far as I can tell, this isn't doable with the ASA, since multiple context mode prohibits the use of remote access VPN, and I can't think of any other work-around than either having individual firewalls running in single context mode for each tenant, or demand that all tenants are interoperable routing-wise and configure a separate ip address pool in a single context mode for each tenant.
 
Essentially, there's no good way to implement this with multiple virtual firewalls, using cisco firewalls?

View 1 Replies View Related

Cisco Firewall :: Backup ASA 5510 Multiple Context Mode

Oct 19, 2011

I am running a ASA 5510 in multiple context mode. IOS 6.4(2), ASDM 6.4(5)106.
 
In older ios/asdm versions it was possible to backup the configuration using ASDM.

In 6.4(5)106 i am missing this feature (see attachment)
 
Is it possible to backup a multiple context firewall using ASDM and above mentioned software versions?

View 3 Replies View Related

Cisco Firewall :: Multiple Context Active / Standby (ASA 5520)

Mar 8, 2013

I need to configure multiple context mode with active/standby failover solution.
 
Even after reading some Cisco documents I still can't understand if active/standby failover configuration has to be done within the admin context only or also within every single context (context-1, context-2 for example). In this case I have to allocate as failover interface a subinterface for each context (admin, context-1, context-2), right ?
 
Therefore a I have an other question: within the admin context, in a failover solution, do I have to allocate all interfaces I want to be moniotred, even though some will be used by context-1 only context and some others will be used by context-2 only context ?
 
An other question is: if active/standby failover configuration has to be done within each context, can I set regular failover within context-1 while stateful failover within context-2 ?
 
The last question is: can I use management interface within all 3 contexts ?

View 8 Replies View Related

Cisco Firewall :: ASA OS 8.5 And VPN On Security Context

Oct 25, 2011

What are the new features added or going to be available on the 8.5 release on the ASA. Would this release "finally" support VPN on multi security context mode.
 
By the sounds of things looks like every other major vendor supports this feature except Cisco.

View 2 Replies View Related

Cisco Firewall :: Migrate To Multiple Context Mode On ASA 5520s Cluster?

Jun 4, 2012

I have a pair of ASA 5520s in active/standby failover mode, single context.  I'll be migrating to multiple context mode later this week.  Do I need to break failover first?  Or if I don't need to, should I?  Or can I do this while maintaining failover?  Can either of these scenarios will work (or fail).  I'll be remote, doing my work via SSH, but have somebody local who can console in if needed.
 
Migration option #1
Log into active/primary ASA
Configure Multiple Context mode
Reboot both devices
Login to active/primary ASA

[code]....

View 1 Replies View Related

Cisco Firewall :: ASA5540 In Multiple-context SNMP / Icmp Doesn't Work

Jun 10, 2013

what´s going on with an asa540 configure in multiple-context mode.   I Have a cacti server on my lan and now I´m try to monitoring the interface with snmp. When I try to get this information returns the error message:
 
CISCOASA/CONTEXTA#
JUN 11 2013 01:52:00: %ASA-1-1-6021: Deny UDP reverse path check from 10.6.6.6 to IP_SRV_CACTI on interface inside
JUN 11 2013 01:52:01: %ASA-1-1-6021: Deny UDP reverve path check from 10.6.6.6 to IP_SRV_CACTI on interface inside
 
If I try to ping returns the same error:
 
CISCOASA/CONTEXTA#
 JUN 11 2013 01:56:09: %ASA-1-1-6021: Deny icmp  reverse path check from 10.6.6.6 to IP_SRV_CACTI on interface inside
   
Following attached the conf of my asa   My question is Why I can´t ping or even use snmp ?

View 5 Replies View Related

Cisco Firewall :: ASA5510 With Multiple Context Mode / Does It Support Remote Access VPN

Jul 17, 2012

I have 2xASA5510 with securityPlus license.i have configured 3 context and Active/Active Failover.Everything works fine. But also want to use rometeAccessVPN but couldn't fine anything for VPN. does it support VPN in multiple mode?

View 3 Replies View Related

Cisco Firewall :: 6500 - FWSM With Multiple Connections?

Aug 29, 2012

There is a 6500 switch with fwsm. We have extended 2 vlans from the ISP into the FWSM. Also there are atleast 10 other vlans for our internal network. We would like say half of the internal vlans to go out of the 1st ISP vlan and the remaining half from the 2nd ISP vlan. Is there a way we can do this in the FWSM?

View 2 Replies View Related

Cisco Firewall :: ASA5510 Single Mode / Move To Multi Context Mode

Sep 16, 2012

I got an ASA 5510 system currently in single context mode, with CSC SSM installed. Single ISP uplink to internet, no VPN. And now customer would like add another ISP uplink, without invest another box for HA.What come across my mind is make the current box into multi context. There's some area i need to concern and also need yours perspective on it.
 
Question 1: For making the firewall into multi context, am i need to do it from scratch, issue mode multiple command. Then rebuilt the current production config into one of the context, then another context meant for the new IPS uplink, and one admin context?
 
Question 2: For CSC -SSM licensing requirement, model ASA 5510 with security plus license is able to support 2 context. So if i split my firewall like what i mention in question, what exactly number of context do i own (admin, context A, context B)?
 
Question 3: For CSC-SSM module in multi context mode, so the management port of CSC SSM must attach at admin context?
 
Question 4: After configured all the policy and traffic to scan, how exactly i should do in order apply this policy to the interface?  Should i only enable at admin context, then firewall service-policy rules, and apply it global, OR should i also do the same action on context A and Context B?

View 3 Replies View Related

Cisco Firewall :: ASA5510 - Implementing Security Context

Oct 29, 2012

I have a ASA 5510 and planning to implement multiple context in a 2  tier security level and vrf-lite. meaning I have 2xASA facing the  internet and below that a 2x3560 switch for our extranet and below that  is another 2xASA for intranet. See diagram below. In this kind of  network I want to know how it would impact the total throughput and  resources of the ASA using multiple context?
 
 
      INTERNET
        |          |
        |          |
2811A         2811B
    |                  |
    |                  |     (OUTSIDE)
ASA_A-------ASA_B
    |                  |     (INSIDE)
    |                  |   
3560A---------3560B
    |                  |    
    |                  |    (INSIDE)
ASA_C--------ASA_D
    |                  |
    |                  |    (OUTSIDE)
3560C----------3560B
    |                  |
INTERNAL NETWORK

View 3 Replies View Related

Cisco Firewall :: Security Context License On 5550

Dec 9, 2012

 I need your support for upgrading the Security context license on 5550, at present we have 5 Security context license installed in ASA but we want it to increased till 10 conctexts. I want to understand if we need to get addtional 5 Security context license or 10.     

View 5 Replies View Related

Cisco Firewall :: ASA 5585x Security Context In HA Cluster

Jun 6, 2012

I have a active-active setup with 2 cisco asa 5585x running 8.4 - the boxes ahve each 2 sec context's build-in - which gives 4 sec context in the cluster. I have 2 x 5 extra licenses (2 x ASA5500-SC-5)  which I haven't applied yet - will this give me a total of 10 or 14 security contextes? I am a bit in doubt because if I only get 10 sec contextes in this cluster then could I instead get a single 10 security context license (1 x ASA5500-SC-10) and add this - hereby I would get 12 then. 

View 1 Replies View Related

Cisco Firewall :: Security Context License Requirement - ASA5520

Jan 14, 2013

A simple question - I have ASA 5520s and was wondering what license is required to create multiple (more than default 2) security contexts.

The ASA already have ASA 5520 VPN Plus license.
 
Software Version 8.4(1)

View 2 Replies View Related

Cisco Firewall :: 6500 - Applying Multiple FWSM Rules Changes In A Batch

Jun 26, 2011

I'm using ASDM 6.2 with a FWSM on a 6500.
 
At the moment everytime I want to make a change to firewall rules I click apply and the rules are applied Immediately. I have to make multiple changes during the working day which I don't like to do.
 
What I would like to do is make changes during the day but not apply them until out of hours (some sort of batch mode). Like I can do in my check point firewalls.

View 1 Replies View Related

Cisco Firewall :: ASA5510 Security Context License Transfer To Another Device

Apr 30, 2012

Is it possivble to have 10 security licenses, license to a Cisco 5510 and have them transfeered to a Cisco5520?    

View 1 Replies View Related

Cisco Firewall :: ASA 5510 / Multiple VLANs Behind Single Firewall Segment?

Feb 5, 2012

I need to create a firewalled segment that not only separates hosts from general population, but also from each other.  The solitary confinement of firewalled segments.I know that I could create a bunch of sub-interfaces, one for each host or group that needs to be isolated, but I'd really rather not have to do that if possible.  1) It could become a management nightmare between ACLs and sub-interfaces and 2) it's a waste of IP addresses.s there any way that I can create a bunch of separate VLANs behind the firewall and have them all terminate at the firewall, using a single firewall IP address for the gateway?
 
VLAN 1 - hosts 1.1.1.5 and 1.1.1.6VLAN 2 - hosts 1.1.1.7
Firewall DMZ Interface - 1.1.1.1VLAN 3 - hosts 1.1.1.8 and 1.1.1.9 

This way, the hosts are isolated and can't talk to each other unless they're on the same VLAN.I'm working with an ASA 5510 running 8.2.4(4).

View 1 Replies View Related

Cisco Switching/Routing :: Catalyst 6513 - FWSM Module Configuration

Dec 20, 2007

My company has acquired a Catalyst 6513 with a FWSM module installed on it. I have been reading lot of documentation on [URL], but still have some problems configuring the FWSM:
 
The 6513 has 10 SVIs configured, each of them with an IP address. These 10 SVIs are binded to 10 VLANs which I need to secure. These SVIs are used for routing all the Inter-VLAN traffic inside the switch. The documentation says it is recommended to use just one SVIs for connecting the switch to the FWSM, although you can use more than one using the command "firewall multiple-vlan-interfaces". I don't want to use this command because it seems a pretty more difficult configuration, since you have to use policy routing after using this command (or that is, at least, what documentation says).
 
When I try to "send" to the FWSM more than one VLAN that are configured as SVIs on the switch I get this error message:
 
"No more than one svi is allowed, command rejected."

If I delete the IP address of those SVIs, then I can to "send" those SVIs to the switch with no problem at all. But I need the SVIs to have IP address configured, since they are needed for routing Inter-V LAN traffic.
 
So, the question is: how can I route all the inter-VLAN traffic using just one SVI on the switch? Should I use the FWSM for inter-VLAN traffic routing?

View 15 Replies View Related

Cisco Firewall :: 2121 / How To Nat Multiple FTP Local Servers From One Single IP

Apr 24, 2013

I have a FTP server at my local network and i have natted the private IP with my Public IP using default FTP Port ( 21) , now i have created Diffrent FTP Account in my server using port 2121 and i am able to login using the private IP with port 2121 , now i want to nat with my public IP with port 2121 and i failed,

1) 125.x.x.x --------- 10.10.1.x : 21 ( Able to access from external network)
 
2) 125.x.x.x ---------- 10.10.1.x : 2121 ( not able to login from external network and able to login internally )

View 7 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved