<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FWSM - DMZ VLAN in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fwsm-dmz-vlan/m-p/762844#M1001990</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mark &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Glad you got it sorted. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As for a book. TO be honest i recommend you save the money and download the relevant configuration guide from Cisco web site. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the one for FWSM 2.3.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/fwsm/fwsm23/configuration/guide/fwsm_cfg.html" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/fwsm/fwsm23/configuration/guide/fwsm_cfg.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 11 Jul 2007 05:36:04 GMT</pubDate>
    <dc:creator>Jon Marshall</dc:creator>
    <dc:date>2007-07-11T05:36:04Z</dc:date>
    <item>
      <title>FWSM - DMZ VLAN</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-dmz-vlan/m-p/762835#M1001974</link>
      <description>&lt;P&gt;I have just setup a 6513 with a firewall module running 2.3(4) software. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured the Vlans and put them in the Firewall Vlan group.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I assigned the IP's on the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I do not understand is this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a DMZ that is VLAN 600&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the 6513 do I need to assign a default IP to this Vlan?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have 10.15.32.2 at security 60 on the pix in Vlan 600&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What steps do I need to take to make sure I have this setup correctly?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 10:42:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-dmz-vlan/m-p/762835#M1001974</guid>
      <dc:creator>markkingery</dc:creator>
      <dc:date>2019-03-11T10:42:50Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM - DMZ VLAN</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-dmz-vlan/m-p/762836#M1001975</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mark &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this is a DMZ on the FWSM then all you want on the 6513 switch is a layer 2 vlan which you have already done and allocated to the FWSM and depending on how you are doing your routing you may need a static route on the 6513 for the DMZ subnet with the next hop being the outside interface of your FWSM. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What you don't want is a layer 3 SVI on your 6513 or traffic will route round the FWSM to get to the DMZ. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You would then need to redistribute that static route into your IGP that you use on your network. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are running your FWSM in single mode you can also run OSPF on it and allow it to dynamically advertise it's DMZ subnets. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Jul 2007 16:05:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-dmz-vlan/m-p/762836#M1001975</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-07-10T16:05:07Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM - DMZ VLAN</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-dmz-vlan/m-p/762837#M1001976</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Correct it is a DMZ for the FWSM only.  &lt;/P&gt;&lt;P&gt;Here is my basic config of the FWSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWSM Version 2.3(4) &lt;/P&gt;&lt;P&gt;nameif Vlan30 inside security100&lt;/P&gt;&lt;P&gt;nameif Vlan700 outside security0&lt;/P&gt;&lt;P&gt;nameif Vlan600 server security60&lt;/P&gt;&lt;P&gt;ip address inside 10.55.0.17 255.255.255.0&lt;/P&gt;&lt;P&gt;ip address outside 156.47.55.8 255.255.255.0&lt;/P&gt;&lt;P&gt;ip address server 10.55.32.2 255.255.255.0&lt;/P&gt;&lt;P&gt;icmp permit any inside&lt;/P&gt;&lt;P&gt;icmp permit any server&lt;/P&gt;&lt;P&gt;pdm location F51-DMZ 255.255.255.255 server&lt;/P&gt;&lt;P&gt;no pdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 156.47.55.10&lt;/P&gt;&lt;P&gt;global (server) 1 10.55.32.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route inside 10.0.0.0 255.0.0.0 10.55.1.1 1&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 156.47.55.1 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What route would I need to put on the 6513 to allow the inside network to be able to route correctly, and then it is my understanding that I now have to allow the inside network to talk to the lower security?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Jul 2007 16:24:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-dmz-vlan/m-p/762837#M1001976</guid>
      <dc:creator>markkingery</dc:creator>
      <dc:date>2007-07-10T16:24:39Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM - DMZ VLAN</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-dmz-vlan/m-p/762838#M1001979</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mark &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On a standlaone ASA/pix you don't need access-lists to go from a higher to a lower interface but as you rightly point out here with the FWSM. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As for routing where are your clients in relation the FWSM inside interface. If they are on the same subnet as the FWSM inside interface then you don't need a route.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If they are are on different vlans then you would need on your 6513 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip route 10.55.32.0 255.255.255.0 10.55.0.17 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But this will only add it to the 6513. If all your clients are on the 6513 or the 6513 is responsible for all your intervlan routing then that will do it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Jul 2007 16:35:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-dmz-vlan/m-p/762838#M1001979</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-07-10T16:35:57Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM - DMZ VLAN</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-dmz-vlan/m-p/762839#M1001981</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok I have this configued and I am new to the FWSM and I appreciate your help. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My next question for help, is I want to ping DMZ host from the inside network to the DMZ.  I would love to see a simple config to allow me to do this. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Jul 2007 16:43:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-dmz-vlan/m-p/762839#M1001981</guid>
      <dc:creator>markkingery</dc:creator>
      <dc:date>2007-07-10T16:43:46Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM - DMZ VLAN</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-dmz-vlan/m-p/762840#M1001984</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mark &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Inside network  = 10.55.0.0 255.255.0.0 &lt;/P&gt;&lt;P&gt;DMZ host    = 10.55.32.10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list acl_inside permit icmp 10.55.0.0 255.255.0.0 host 10.55.32.10 echo&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group acl_inside in interface inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list acl_dmz permit icmp host 10.55.32.10 10.55.0.0 255.255.0.0 echo-reply&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group acl_dmz in interface server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 1 10.55.0.0 &lt;/P&gt;&lt;P&gt;global (server) 1 interface &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Jul 2007 16:56:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-dmz-vlan/m-p/762840#M1001984</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-07-10T16:56:52Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM - DMZ VLAN</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-dmz-vlan/m-p/762841#M1001987</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do I still need to apply the access list to an access group on this version?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Jul 2007 17:06:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-dmz-vlan/m-p/762841#M1001987</guid>
      <dc:creator>markkingery</dc:creator>
      <dc:date>2007-07-10T17:06:45Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM - DMZ VLAN</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-dmz-vlan/m-p/762842#M1001988</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mark &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, sorry about that, i did edit the previous post to add those lines into the config. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Jul 2007 17:07:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-dmz-vlan/m-p/762842#M1001988</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-07-10T17:07:50Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM - DMZ VLAN</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-dmz-vlan/m-p/762843#M1001989</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I got it working.  Thanks for your help.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to find a good book on the FWSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Jul 2007 18:38:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-dmz-vlan/m-p/762843#M1001989</guid>
      <dc:creator>markkingery</dc:creator>
      <dc:date>2007-07-10T18:38:17Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM - DMZ VLAN</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-dmz-vlan/m-p/762844#M1001990</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mark &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Glad you got it sorted. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As for a book. TO be honest i recommend you save the money and download the relevant configuration guide from Cisco web site. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the one for FWSM 2.3.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/fwsm/fwsm23/configuration/guide/fwsm_cfg.html" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/fwsm/fwsm23/configuration/guide/fwsm_cfg.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jul 2007 05:36:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-dmz-vlan/m-p/762844#M1001990</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-07-11T05:36:04Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM - DMZ VLAN</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-dmz-vlan/m-p/762845#M1001991</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My next question is what do I need to do on the DMZ interface to allow hosts to talk to each other in the DMZ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jul 2007 18:51:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-dmz-vlan/m-p/762845#M1001991</guid>
      <dc:creator>markkingery</dc:creator>
      <dc:date>2007-07-19T18:51:35Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM - DMZ VLAN</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-dmz-vlan/m-p/762846#M1001992</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I got it fixed, it was a load balance issue. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jul 2007 19:31:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-dmz-vlan/m-p/762846#M1001992</guid>
      <dc:creator>markkingery</dc:creator>
      <dc:date>2007-07-19T19:31:02Z</dc:date>
    </item>
  </channel>
</rss>

