Configuring Csm B (Stealth Firewall Example) - Cisco catalyst 6500 series Configuration Note

Content switching module
Hide thumbs Also See for catalyst 6500 series:
Table of Contents

Advertisement

Configuring Stealth Firewall Load Balancing
Command
Step 15
Switch-A(config-slb-vserver)# virtual
10.1.0.0 255.255.255.0 any
Step 16
Switch-A(config-slb-vserver))# vlan 10
Step 17
Switch-A(config-slb-vserver)# serverfarm
TO-INSIDE-SF
Step 18
Switch-A(config-slb-vserver)# inservice
1.
2.
3.
4.
5.
6.
7.

Configuring CSM B (Stealth Firewall Example)

To create the regular configuration example, perform the following configuration tasks for CSM B:
Although the configuration tasks are the same for both CSM A and CSM B, the steps, commands, and
Note
parameters that you enter are different.
Creating VLANs on Switch B
To create three VLANs on Switch B, perform this task:
This example assumes that the CSMs are in separate Catalyst 6500 series switches. If they are in the
Note
same chassis, you can create all of the VLANs on the same Catalyst 6500 series switch console.
Command
Step 1
Switch-B(config)# vlan
Step 2
Switch-B(vlan)# vlan 102
Step 3
Switch-B(vlan)# vlan 104
Step 4
Switch-B(vlan)# vlan 200
1.
2.
Catalyst 6500 Series Content Switching Module Configuration Note
11-12
FORWARD-V101 allows Internet traffic to reach the insecure side of the firewalls (through VLAN 101).
Client matching is only limited by VLAN restrictions. (See Step 4.)
This server farm is actually a forwarding predictor rather than an actual server farm containing real servers.
FORWARD-V103 allows Internet traffic to reach the insecure side of the firewalls (through VLAN 103).
Clients will always match–only being limited by VLAN restrictions. (See Step 10.)
OUTSIDE-VS allows traffic from the Internet to reach CSM A (through VLAN 10).
The server farm contains the alias IP addresses of CSM B that lie along the path of Firewall 1 and Firewall 2.
Creating VLANs on Switch B, page 11-12
Configuring VLANs on CSM B, page 11-13
Configuring Server Farms on CSM B, page 11-13
Configuring Virtual Servers on CSM B, page 11-15
Do this step on the switch console of the switch that contains CSM B.
VLAN 102 provides a connection through Firewall 1 to CSM A.
Chapter 11
Configuring Firewall Load Balancing
Purpose
Specifies the IP address, netmask, and protocol (any)
for this virtual server. Clients reach the server farm
represented by this virtual server through this
address.
Specifies that the virtual server will only accept
traffic arriving on VLAN 10, which is traffic arriving
from the Internet.
Specifies the server farm for this virtual server
Enables the virtual server.
Purpose
1
Enters the VLAN mode
.
2
Creates VLAN 102
.
3
Creates VLAN 104
.
4
Creates VLAN 200
.
7
.
OL-4612-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

Catalyst 6000 series

Table of Contents