Firewall Configuration Guidelines And Restrictions - Cisco 6500 Series Software Configuration Manual

Hide thumbs Also See for 6500 Series:
Table of Contents

Advertisement

Configuring the Cisco IOS Firewall Feature Set
Catalyst 6500 series switches support the Intrusion Detection System Module (IDSM)
Note
(WS-X6381-IDS). Catalyst 6500 series switches do not support the Cisco IOS firewall IDS feature,
which is configured with the ip audit command.

Firewall Configuration Guidelines and Restrictions

Follow these guidelines and restrictions when configuring the Cisco IOS firewall features:
Restrictions
Guidelines
Catalyst 6500 Series Switch Cisco IOS Software Configuration Guide—Release 12.1 E
23-6
Security server support
Network address translation
Neighbor router authentication
Event logging
User authentication and authorization
On other platforms, if you enter the ip inspect command on a port, CBAC modifies ACLs on other
ports to permit the inspected traffic to flow through the network device. On Catalyst 6500 series
switches, you must enter the mls ip inspect commands to permit traffic through any ACLs that
would deny the traffic through other ports. See the
Switches" section on page
With Supervisor Engine 2 and PFC2, reflexive ACLs and CBAC have conflicting flow mask
requirements. When you configure CBAC on a switch with Supervisor Engine 2 and PFC2, reflexive
ACLs are processed in software on the MSFC2.
CBAC is incompatible with VACLs. You can configure both CBAC and VACLs on the switch but
not in the same subnet (VLAN) or on the same interface.
Note
The Intrusion Detection System Module (IDSM) uses VACLs to select traffic. To use the
IDSM in a subnet where CBAC is configured, enter the mls ip ids acl_name interface
command, where acl_name is configured to select traffic for the IDSM.
To inspect Microsoft NetMeeting (2.0 or greater) traffic, turn on both h323 and tcp inspection.
To inspect web traffic, turn on tcp inspection. To avoid reduced performance, do not turn on http
inspection to block Java.
You can configure CBAC on physical ports configured as Layer 3 interfaces and on VLAN
interfaces.
QoS and CBAC do not interact or interfere with each other.
"Configuring CBAC on Catalyst 6500 Series
23-7.
Chapter 23
Configuring Network Security
78-14099-04

Advertisement

Table of Contents
loading

Table of Contents