Regular Firewall Configuration Example - Cisco catalyst 6500 series Configuration Note

Content switching module
Hide thumbs Also See for catalyst 6500 series:
Table of Contents

Advertisement

Chapter 11
Configuring Firewall Load Balancing
Figure 11-7 Regular Firewall Configuration Example
Traffic to
Intranet
Router
CSM-A
IP address
100.0.0.13
1
Internet
VLAN 100
Item
Traffic Direction
1
To intranet
2
To intranet
3
To Internet
4
To Internet
Figure 11-7
(CSM A and CSM B). Traffic enters and exits the firewalls through shared VLANs (VLAN 101 and
VLAN 201). Both regular firewalls have unique addresses on each shared VLAN.
VLANs provide connectivity to the Internet (VLAN 100), the internal network (VLAN 200), and to
internal server farms (VLAN 20).
The CSM balances traffic among regular firewalls as if they were real servers. Regular firewalls are
configured in server farms with IP addresses like real servers. The server farms to which regular firewalls
belong are assigned a load-balancing predictor and are associated with virtual servers.

Regular Firewall Configuration Example

The regular firewall configuration example contains two CSMs (CSM A and CSM B) installed in
separate Catalyst 6500 series switches.
You can use this example when configuring two CSMs in the same Catalyst 6500 series switch chassis.
Note
You can also use this example when configuring a single CSM in a single switch chassis, assuming that
you specify the slot number of that CSM when configuring both CSM A and CSM B.
OL-4612-01
Firewall 1
IP address
100.0.0.3
Catalyst 6500
IP address
VLAN 101
100.0.0.25
4
IP address
100.0.0.4
Firewall 2
Arrives On
VLAN 100
VLANs 201
VLAN 200 and 20
VLANs 101
shows two regular firewalls (Firewall 1 and Firewall 2) located between two CSMs
IP address
200.0.0.3
Catalyst 6500
2
VLAN 201
IP address
200.0.0.26
IP address
IP address
10.1.0.26
200.0.0.4
Exits On
VLANs 101
VLAN 200 and 20
VLANs 201
VLAN 100
Catalyst 6500 Series Content Switching Module Configuration Note
Configuring Regular Firewall Load Balancing
VLAN 200
IP address
200.0.0.x
CSM-B
Internal
network
IP address
200.0.0.x
Traffic to
3
Internet
IP address
VLAN 20
10.1.0.x
11-17

Advertisement

Table of Contents
loading

This manual is also suitable for:

Catalyst 6000 series

Table of Contents