Cisco Catalyst 6500 Series Configuration Manual page 72

Catalyst 6500 series switch and cisco 7600 series router firewall services
Hide thumbs Also See for Catalyst 6500 Series:
Table of Contents

Advertisement

Firewall Mode Overview
An Outside User Visits a Website on the Inside Network
Figure 4-3
Figure 4-10 Outside to Inside
The steps below describe how data moves through the FWSM (see
1.
2.
3.
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide
4-14
shows an outside user accessing the inside website.
Host
Internet
Switch
209.165.201.2
VLAN 100
VLAN 200
209.165.201.1
209.165.200.230
Web Server
209.165.200.225
A user on the outside network requests a web page from the inside website.
The FWSM receives the packet on VLAN 100 and, because it is a new session, it verifies that the
packet is allowed according to the terms of the security policy (ACLs, filters, AAA).
For multiple context mode, the FWSM first classifies the packet according to either a unique VLAN
or a unique destination address. In this case, the VLAN would be unique. For transparent firewall
mode, each context has a unique VLAN on the inside and outside, so the IP address would not be
considered.
The FWSM records that a session is established.
FWSM
209.165.201.6
Chapter 4
Configuring the Firewall Mode
Figure
4-3):
OL-6392-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

7600 series

Table of Contents