Cisco Catalyst 6500 Series Configuration Manual page 62

Catalyst 6500 series switch and cisco 7600 series router firewall services
Hide thumbs Also See for Catalyst 6500 Series:
Table of Contents

Advertisement

Firewall Mode Overview
3.
4.
5.
6.
An Outside User Visits a Website on the DMZ
Figure 4-3
Figure 4-3
Inside
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide
4-4
For multiple context mode, the FWSM first classifies the packet according to either a unique VLAN
or a unique destination address. In this case, the VLAN would be unique; the www.cisco.com
IP address is not located uniquely within a context and is not a unique destination address.
The FWSM translates the local source address (10.1.2.27) to the global address 209.165.201.10,
which is on the outside interface subnet.
The global address could be on any subnet, but routing is simplified when it is on the outside
interface subnet.
The FWSM then records that a session is established and forwards the packet from the outside
interface.
When www.cisco.com responds to the request, the packet goes through the FWSM, and because the
session is already established, the packet bypasses the many lookups associated with a new
connection. The fast path performs NAT by translating the global destination address to the local
user address, 10.1.2.27.
The FWSM forwards the packet to the inside user.
shows an outside user accessing the DMZ website.
Outside to DMZ
User
Outside
Switch
209.165.201.2
FWSM
10.1.2.1
10.1.1.1
Web Server
10.1.1.3
Dest Addr Translation
209.165.201.3
10.1.1.3
DMZ
Chapter 4
Configuring the Firewall Mode
OL-6392-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

7600 series

Table of Contents