Transparent Firewall Guidelines - Cisco 7604 Configuration Manual

Catalyst 6500 series switch and cisco 7600 series router firewall services module configuration guide using the cli
Hide thumbs Also See for 7604:
Table of Contents

Advertisement

Transparent Mode Overview
Figure 5-7
Figure 5-7
Management IP
Bridge Group 1

Transparent Firewall Guidelines

Follow these guidelines when planning your transparent firewall network:
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
5-10
shows two networks connected to the FWSM, which has two bridge groups.
Transparent Firewall Network with Two Bridge Groups
10.1.1.1
10.2.1.1
Management IP
Bridge Group 2
10.1.1.2
10.2.1.2
10.1.1.3
10.2.1.3
A management IP address is required for each bridge group.
Unlike routed mode, which requires an IP address for each interface, a transparent firewall has an
IP address assigned to the entire bridge group. The FWSM uses this IP address as the source address
for packets originating on the FWSM, such as system messages or AAA communications. In
addition to the bridge group management address, you can optionally configure a management
interface; see the
"Management Interface" section on page 5-8
The management IP address must be on the same subnet as the connected network. The FWSM does
not support traffic on secondary networks; only traffic on the same network as the management IP
address is supported. See the
more information about management IP subnets.
Each bridge group uses an inside interface and an outside interface only.
Each directly-connected network must be on the same subnet.
Do not specify the bridge group management IP address as the default gateway for connected
devices; devices need to specify the router on the other side of the FWSM as the default gateway.
The default route for the transparent firewall, which is required to provide a return path for
management traffic, is only applied to management traffic from one bridge group network. This is
because the default route specifies an interface in the bridge group as well as the router IP address
on the bridge group network, and you can only define one default route. If you have management
traffic from more than one bridge group network, you need to specify a static route that identifies
the network from which you expect management traffic.
"Assigning an IP Address to a Bridge Group" section on page 6-6
Chapter 5
Configuring the Firewall Mode
for more information.
OL-20748-01
for

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

7609-s76137606-sCatalyst 6500 series7600 series

Table of Contents