Adding Switched Virtual Interfaces To The Msfc - Cisco 7604 Configuration Manual

Catalyst 6500 series switch and cisco 7600 series router firewall services module configuration guide using the cli
Hide thumbs Also See for 7604:
Table of Contents

Advertisement

Adding Switched Virtual Interfaces to the MSFC

If you configure the VLANs in the FWSM configuration, and then later assign the VLANs to the FWSM
on the switch using this procedure, then those VLANs are brought administratively up on the FWSM
even if they were configured to be shut down. To shut them down, enter the following commands at the
FWSM CLI:
interface vlan number
shutdown
Step 2
To assign the firewall groups to the FWSM, enter the following command:
Router(config)# firewall module module_number vlan-group firewall_group
The firewall_group is one or more group numbers:
Separate numbers or ranges by commas. For example, enter the following numbers:
5,7-10
The following example shows how you can create three firewall VLAN groups: one for each FWSM, and
one that includes VLANs assigned to both FWSMs:
Router(config)# firewall vlan-group 50 55-57
Router(config)# firewall vlan-group 51 70-85
Router(config)# firewall vlan-group 52 100
Router(config)# firewall module 5 vlan-group 50,52
Router(config)# firewall module 8 vlan-group 51,52
The following is sample output from the show firewall vlan-group command:
Router# show firewall vlan-group
Group vlans
----- ------
50 55-57
51 70-85
52 100
The following is sample output from the show firewall module command, which shows all VLAN
groups:
Router# show firewall module
Module Vlan-groups
5
8
Adding Switched Virtual Interfaces to the MSFC
A VLAN defined on the MSFC is called a switched virtual interface. If you assign the VLAN used for
the SVI to the FWSM (see the
page
This section includes the following topics:
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
2-4
A single number (n)
A range (n-x)
50,52
51,52
2-2), then the MSFC routes between the FWSM and other Layer 3 VLANs.
SVI Overview, page 2-5
Chapter 2
"Assigning VLANs to the Firewall Services Module" section on
Configuring the Switch for the Firewall Services Module
OL-20748-01

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

7609-s76137606-sCatalyst 6500 series7600 series

Table of Contents