Configuring Interfaces For Transparent Firewall Mode; Information About Interfaces In Transparent Mode; Information About Bridge Groups; Information About Device Management - Cisco 7604 Configuration Manual

Catalyst 6500 series switch and cisco 7600 series router firewall services module configuration guide using the cli
Hide thumbs Also See for 7604:
Table of Contents

Advertisement

Configuring Interfaces for Transparent Firewall Mode

The following example configures parameters in multiple context mode for the context configuration.
The interface ID is a mapped name.
hostname/contextA(config)# interface int1
hostname/contextA(config-if)# nameif outside
hostname/contextA(config-if)# security-level 100
hostname/contextA(config-if)# ip address 10.1.2.1 255.255.255.0
Configuring Interfaces for Transparent Firewall Mode
This section includes the following topics:

Information About Interfaces in Transparent Mode

This section includes the following topics:

Information About Bridge Groups

A transparent firewall connects the same network on its inside and outside interfaces. Each pair of
interfaces belongs to a bridge group, to which you must assign a management IP address. You can
configure up to eight bridge groups of two interfaces each. Each bridge group connects to a separate
network. Bridge group traffic is isolated from other bridge groups; traffic is not routed to another bridge
group within the FWSM, and traffic must exit the FWSM before it is routed by an external router back
to another bridge group in the FWSM.
You might want to use more than one bridge group if you do not want the overhead of security contexts,
or want to maximize your use of security contexts. Although the bridging functions are separate for each
bridge group, many other functions are shared between all bridge groups. For example, all bridge groups
share a system log server or AAA server configuration. For complete security policy separation, use
security contexts with one bridge group in each context.
The FWSM does not support traffic on secondary networks; only traffic on the same network as the
Note
management IP address is supported.

Information About Device Management

For device management, you have two available mechanisms:
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
6-4
Information About Interfaces in Transparent Mode, page 6-4
Configuring Transparent Firewall Interfaces for Through Traffic, page 6-6
Assigning an IP Address to a Bridge Group, page 6-6
Adding a Management Interface, page 6-7
Information About Bridge Groups, page 6-4
Information About Device Management, page 6-4
Guidelines and Limitations, page 6-5
Any bridge group management address—Connect to the bridge group network on which your
management station is located.
Chapter 6
Configuring Interface Parameters
OL-20748-01

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

7609-s76137606-sCatalyst 6500 series7600 series

Table of Contents