Unsupported Features In Transparent Mode - Cisco 7604 Configuration Manual

Catalyst 6500 series switch and cisco 7600 series router firewall services module configuration guide using the cli
Hide thumbs Also See for 7604:
Table of Contents

Advertisement

Chapter 5
Configuring the Firewall Mode

Unsupported Features in Transparent Mode

Table 5-1
Table 5-1
Unsupported Feature
DHCP relay
Dynamic routing protocols
IPv6 for the bridge group IP address or
management interface IP address
LoopGuard on the switch
Multicast
Remote access VPN for management
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
For multiple context mode, each context must use different interfaces; you cannot share an interface
across contexts. The only exception to this is for an optional management VLAN, which can be
shared across multiple contexts.
For multiple context mode, each context typically uses different subnets. You can use overlapping
subnets, but your network topology requires router and NAT configuration to make it possible from
a routing standpoint.
You must use an extended access list to allow Layer 3 traffic, such as IP traffic, through the FWSM.
You can also optionally use an EtherType access list to allow non-IP traffic through.
lists features that are not supported in transparent mode.
Unsupported Features in Transparent Mode
Description
The transparent firewall can act as a DHCP server, but it does
not support the DHCP relay commands. DHCP relay is not
required because you can allow DHCP traffic to pass through
using an extended access list.
You can, however, add static routes for traffic originating on
the FWSM. You can also allow dynamic routing protocols
through the FWSM using an extended access list.
You can, however, pass the IPv6 EtherType using an
EtherType access list.
Do not enable LoopGuard globally on the switch if the
FWSM is in transparent mode. LoopGuard is automatically
applied to the internal EtherChannel between the switch and
the FWSM, so after a failover and a failback, LoopGuard
causes the secondary unit to be disconnected because the
EtherChannel goes into the err-disable state.
You can, however, allow multicast traffic through the FWSM
by allowing it in an extended access list.
You can use site-to-site VPN for management.
Transparent Mode Overview
5-11

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

7609-s76137606-sCatalyst 6500 series7600 series

Table of Contents