EasyManuals Logo
Home>Cisco>Switch>Catalyst 6500 Series

Cisco Catalyst 6500 Series User Manual

Cisco Catalyst 6500 Series
392 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #69 background imageLoading...
Page #69 background image
4-11
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide
OL-6392-01
Chapter 4 Configuring the Firewall Mode
Firewall Mode Overview
Transparent Firewall Guidelines
Follow these guidelines when planning your transparent firewall network:
The transparent FWSM uses an inside interface and an outside interface only.
Each directly connected network must be on the same subnet.
A management IP address is required for each context, even if you do not intend to use Telnet to the
context.
The FWSM uses this IP address as the source address for packets originating on the FWSM, such
as system messages or AAA communications.
The management IP address must be on the same subnet as the connected network.
Do not specify the FWSM management IP address as the default gateway for connected devices;
devices need to specify the router on the other side of the FWSM as the default gateway.
Each interface must be a different VLAN interface.
For multiple context mode, each context must use different VLANs; you cannot share a VLAN
across contexts.
For multiple context mode, each context can use the same (overlapping) subnet or different subnets.
Make sure that the upstream router performs NAT if you use overlapping subnets.
Dynamic routing protocols are neither required nor supported.
You can, however, add static routes.
NAT is not supported.
NAT is performed on the upstream router. However, you can configure some parameters available
only in the static command. See the “Configuring Connection Limits for Non-NAT Configurations”
section on page 6-10 for more information.
You must use an extended ACL to allow Layer 3 traffic, such as IP traffic, through the FWSM.
You can also optionally use an EtherType ACL to allow non-IP traffic through.

Table of Contents

Other manuals for Cisco Catalyst 6500 Series

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco Catalyst 6500 Series and is the answer not in the manual?

Cisco Catalyst 6500 Series Specifications

General IconGeneral
BrandCisco
ModelCatalyst 6500 Series
CategorySwitch
LanguageEnglish

Related product manuals