<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I enable 8 pairs of interfaces per context in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-do-i-enable-8-pairs-of-interfaces-per-context/m-p/667914#M1010300</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was trying to create more than one bridge group per context yesterday but I was not able to configure more than 2 interfaces in the context, so I am guessing how can you enable up to eight bridge groups in a context if you are not able to configure more than 2 interfaces per context. If you could try it at your lab please let me know the results, I will keep looking for the way to configure more than one bridge group per context.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 15 Mar 2007 19:25:46 GMT</pubDate>
    <dc:creator>vicente.madrigal</dc:creator>
    <dc:date>2007-03-15T19:25:46Z</dc:date>
    <item>
      <title>How do I enable 8 pairs of interfaces per context</title>
      <link>https://community.cisco.com/t5/network-security/how-do-i-enable-8-pairs-of-interfaces-per-context/m-p/667910#M1010296</link>
      <description>&lt;P&gt;I have my FWSM working in transparent mode with 3 context (one admin, and 2 aditional contexts) I am trying to configure 8 pairs of interfaces in one of my contexts (according to the documentation it is possible) but when I tried to enter more than 2 vlan interfaces in the context, I get this message: ERROR: Context interface limit of 2 reached on 'vlan4'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I configure the 8 pairs of interfaces in one context?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:46:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-do-i-enable-8-pairs-of-interfaces-per-context/m-p/667910#M1010296</guid>
      <dc:creator>vicente.madrigal</dc:creator>
      <dc:date>2019-03-11T09:46:59Z</dc:date>
    </item>
    <item>
      <title>Re: How do I enable 8 pairs of interfaces per context</title>
      <link>https://community.cisco.com/t5/network-security/how-do-i-enable-8-pairs-of-interfaces-per-context/m-p/667911#M1010297</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Vicente &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My understanding was that with the FWSM in transparent mode each context can only support 2 vlans because it is in effect bridging between the 2. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you point me at the docs where it says you can use more than 2 vlans in on the same context. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Mar 2007 18:19:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-do-i-enable-8-pairs-of-interfaces-per-context/m-p/667911#M1010297</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-03-15T18:19:16Z</dc:date>
    </item>
    <item>
      <title>Re: How do I enable 8 pairs of interfaces per context</title>
      <link>https://community.cisco.com/t5/network-security/how-do-i-enable-8-pairs-of-interfaces-per-context/m-p/667912#M1010298</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the doc: &lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/partner/products/hw/switches/ps708/products_module_configuration_guide_chapter09186a0080577c38.html#wp1220151" target="_blank"&gt;http://www.cisco.com/en/US/partner/products/hw/switches/ps708/products_module_configuration_guide_chapter09186a0080577c38.html#wp1220151&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is what it says regarding bridge groups:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Bridge Groups &lt;/P&gt;&lt;P&gt;If you do not want the overhead of security contexts, or want to maximize your use of security contexts, you can configure up to eight pairs of interfaces, called bridge groups. Each bridge group connects to a separate network. Bridge group traffic is isolated from other bridge groups; traffic is not routed to another bridge group within the FWSM, and traffic must exit the FWSM before it is routed by an external router back to another bridge group in the FWSM. Although the bridging functions are separate for each bridge group, many other functions are shared between all bridge groups. For example, all bridge groups share a system log server or AAA server configuration. For complete security policy separation, use security contexts with one bridge group in each context. "&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Mar 2007 18:50:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-do-i-enable-8-pairs-of-interfaces-per-context/m-p/667912#M1010298</guid>
      <dc:creator>vicente.madrigal</dc:creator>
      <dc:date>2007-03-15T18:50:23Z</dc:date>
    </item>
    <item>
      <title>Re: How do I enable 8 pairs of interfaces per context</title>
      <link>https://community.cisco.com/t5/network-security/how-do-i-enable-8-pairs-of-interfaces-per-context/m-p/667913#M1010299</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Vicente&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well you live and learn, i guess that's what Netpro is all about !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an FWSM in our lab at work so i might try this next week. One thing that struck me from the config was the following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"You can only assign two interfaces to a bridge group. You cannot assign the same interface to more than one bridge group"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you definitely using separate vlan interfaces pairs per bridge group ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will look at this in our lab as soon as i can &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Mar 2007 19:09:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-do-i-enable-8-pairs-of-interfaces-per-context/m-p/667913#M1010299</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-03-15T19:09:57Z</dc:date>
    </item>
    <item>
      <title>Re: How do I enable 8 pairs of interfaces per context</title>
      <link>https://community.cisco.com/t5/network-security/how-do-i-enable-8-pairs-of-interfaces-per-context/m-p/667914#M1010300</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was trying to create more than one bridge group per context yesterday but I was not able to configure more than 2 interfaces in the context, so I am guessing how can you enable up to eight bridge groups in a context if you are not able to configure more than 2 interfaces per context. If you could try it at your lab please let me know the results, I will keep looking for the way to configure more than one bridge group per context.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Mar 2007 19:25:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-do-i-enable-8-pairs-of-interfaces-per-context/m-p/667914#M1010300</guid>
      <dc:creator>vicente.madrigal</dc:creator>
      <dc:date>2007-03-15T19:25:46Z</dc:date>
    </item>
    <item>
      <title>Re: How do I enable 8 pairs of interfaces per context</title>
      <link>https://community.cisco.com/t5/network-security/how-do-i-enable-8-pairs-of-interfaces-per-context/m-p/667915#M1010301</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Vicente &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apologies for delay, i had to upgrade our FWSM to version 3.1 before i could test. Specific version of software is 3.1(2). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It works fine for me so here are the steps i followed. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Created vlans 700-708 on the 6500. &lt;/P&gt;&lt;P&gt;2) Allocated these vlans to the FWSM on the switch ie. "firewall vlan-group 7 700-708"&lt;/P&gt;&lt;P&gt;3) Logged on to the FWSM in sys execution space. &lt;/P&gt;&lt;P&gt;4) Created a new context "trs" &amp;amp; allocated vlans 700-708 to that context. &lt;/P&gt;&lt;P&gt;5) Changed to the trs context. Made the context transparent "firewall transparent".&lt;/P&gt;&lt;P&gt;6) Did a sh run and the vlan interfaces from vlan700 -&amp;gt; vlan708 were there. &lt;/P&gt;&lt;P&gt;6) Assigned vlan700,701 to bridge-group 1 &lt;/P&gt;&lt;P&gt;            vlan702,703 to bridge-group 2 etc..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It all worked fine. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this how you have set it up ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What version of the 3.1 software are you using - i can downoad the exact one to test if need be. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Mar 2007 08:33:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-do-i-enable-8-pairs-of-interfaces-per-context/m-p/667915#M1010301</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-03-16T08:33:16Z</dc:date>
    </item>
    <item>
      <title>Re: How do I enable 8 pairs of interfaces per context</title>
      <link>https://community.cisco.com/t5/network-security/how-do-i-enable-8-pairs-of-interfaces-per-context/m-p/667916#M1010302</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I didn't have a chance to come back to our laboratory yesterday. I will try your steps today as soon as poosible. I think the main issue here is the software version I am using in my FWSM. I am going to upgrade to the 3.1 version and I will let you know how it goes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vicente&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Mar 2007 17:42:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-do-i-enable-8-pairs-of-interfaces-per-context/m-p/667916#M1010302</guid>
      <dc:creator>vicente.madrigal</dc:creator>
      <dc:date>2007-03-16T17:42:07Z</dc:date>
    </item>
    <item>
      <title>Re: How do I enable 8 pairs of interfaces per context</title>
      <link>https://community.cisco.com/t5/network-security/how-do-i-enable-8-pairs-of-interfaces-per-context/m-p/667917#M1010303</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Vicente &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How did yout get on ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2007 07:55:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-do-i-enable-8-pairs-of-interfaces-per-context/m-p/667917#M1010303</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-03-21T07:55:09Z</dc:date>
    </item>
    <item>
      <title>Re: How do I enable 8 pairs of interfaces per context</title>
      <link>https://community.cisco.com/t5/network-security/how-do-i-enable-8-pairs-of-interfaces-per-context/m-p/667918#M1010304</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was able to to go to the lab yesterday and tried your steps, it worked fine the problem was the Software version I was using on the FWMS;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;context SIIC&lt;/P&gt;&lt;P&gt;  allocate-interface Vlan107 int107 &lt;/P&gt;&lt;P&gt;  allocate-interface Vlan108 int108 &lt;/P&gt;&lt;P&gt;  allocate-interface Vlan109 int109 &lt;/P&gt;&lt;P&gt;  allocate-interface Vlan7 int7 &lt;/P&gt;&lt;P&gt;  allocate-interface Vlan8 int8 &lt;/P&gt;&lt;P&gt;  allocate-interface Vlan9 int9 &lt;/P&gt;&lt;P&gt;  config-url disk:/SIIC.cfg&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With the new version I was able to allocate more than 2 interfaces in the context. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will dome more test to see if it wokrs fine filterint traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vicente&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Mar 2007 15:57:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-do-i-enable-8-pairs-of-interfaces-per-context/m-p/667918#M1010304</guid>
      <dc:creator>vicente.madrigal</dc:creator>
      <dc:date>2007-03-22T15:57:23Z</dc:date>
    </item>
    <item>
      <title>How do I enable 8 pairs of interfaces per context</title>
      <link>https://community.cisco.com/t5/network-security/how-do-i-enable-8-pairs-of-interfaces-per-context/m-p/667919#M1010305</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have a question related to this, is it possible with the base number of contexts&amp;nbsp; (Admin plus two other) to have three contexts each with 8 pairs of bridge group interfaces ?&amp;nbsp; Or would it be necessary to order additional context licenses ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Aug 2011 11:36:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-do-i-enable-8-pairs-of-interfaces-per-context/m-p/667919#M1010305</guid>
      <dc:creator>markturner</dc:creator>
      <dc:date>2011-08-08T11:36:11Z</dc:date>
    </item>
  </channel>
</rss>

