Cisco ASA Series Cli Configuration Manual page 226

Software version 9.0 for the services module
Hide thumbs Also See for ASA Series:
Table of Contents

Advertisement

Information About Security Contexts
For transparent firewalls, you must use unique interfaces.
on the Context B inside network from the Internet. The classifier assigns the packet to Context B because
the ingress interface is Gigabit Ethernet 1/0.3, which is assigned to Context B.
Figure 1-3
Admin
Context
GE 1/0.1
Cascading Security Contexts
Placing a context directly in front of another context is called cascading contexts; the outside interface
of one context is the same interface as the inside interface of another context. You might want to cascade
contexts if you want to simplify the configuration of some contexts by configuring shared parameters in
the top context.
Note
Cascading contexts requires unique MAC addresses for each context interface (the default setting).
Because of the limitations of classifying packets on shared interfaces without MAC addresses, we do not
recommend using cascading contexts without unique MAC addresses.
Cisco ASA Series CLI Configuration Guide
1-6
Transparent Firewall Contexts
Internet
Classifier
GE 0/0.2
GE 0/0.1
Context A
GE 1/0.2
Admin
Inside
Network
Customer A
Host
Host
10.1.1.13
10.1.2.13
Chapter 1
Figure 1-3
GE 0/0.3
Context B
GE 1/0.3
Inside
Customer B
Host
10.1.3.13
Configuring Multiple Context Mode
shows a packet destined to a host

Advertisement

Table of Contents
loading

Table of Contents