<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Assistance about shared interface between multiple contexts in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/assistance-about-shared-interface-between-multiple-contexts/m-p/613761#M1023868</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Execuse me. I have a deployed FWSM with 2 contexts. The inside is a shared interface and the outside interfaces are unique interfaces. On the shared interface I used identity static translation in the two contexts. Now the traffic cannot go through the context B although can go through the context A. I don't know why. Please help me.&lt;/P&gt;&lt;P&gt;BTW, the topology is as the following.&lt;/P&gt;&lt;P&gt;|--------------|&lt;/P&gt;&lt;P&gt;|  10.0.22.0   |-----------------&lt;/P&gt;&lt;P&gt;|--------------|                |&lt;/P&gt;&lt;P&gt;           |                    |&lt;/P&gt;&lt;P&gt;10.0.22.254|                    |10.0.22.250&lt;/P&gt;&lt;P&gt;|-----------|              |------------|&lt;/P&gt;&lt;P&gt;|Context A  |              | Context B  |&lt;/P&gt;&lt;P&gt;|-----------|              |------------|&lt;/P&gt;&lt;P&gt;| 10.0.9.0                     10.0.5.0 |&lt;/P&gt;&lt;P&gt;|------------              --------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is:&lt;/P&gt;&lt;P&gt;Is there any restrict in this environment?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanking in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ZJ&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 09:43:11 GMT</pubDate>
    <dc:creator>junzhang</dc:creator>
    <dc:date>2019-03-11T09:43:11Z</dc:date>
    <item>
      <title>Assistance about shared interface between multiple contexts</title>
      <link>https://community.cisco.com/t5/network-security/assistance-about-shared-interface-between-multiple-contexts/m-p/613761#M1023868</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Execuse me. I have a deployed FWSM with 2 contexts. The inside is a shared interface and the outside interfaces are unique interfaces. On the shared interface I used identity static translation in the two contexts. Now the traffic cannot go through the context B although can go through the context A. I don't know why. Please help me.&lt;/P&gt;&lt;P&gt;BTW, the topology is as the following.&lt;/P&gt;&lt;P&gt;|--------------|&lt;/P&gt;&lt;P&gt;|  10.0.22.0   |-----------------&lt;/P&gt;&lt;P&gt;|--------------|                |&lt;/P&gt;&lt;P&gt;           |                    |&lt;/P&gt;&lt;P&gt;10.0.22.254|                    |10.0.22.250&lt;/P&gt;&lt;P&gt;|-----------|              |------------|&lt;/P&gt;&lt;P&gt;|Context A  |              | Context B  |&lt;/P&gt;&lt;P&gt;|-----------|              |------------|&lt;/P&gt;&lt;P&gt;| 10.0.9.0                     10.0.5.0 |&lt;/P&gt;&lt;P&gt;|------------              --------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is:&lt;/P&gt;&lt;P&gt;Is there any restrict in this environment?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanking in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ZJ&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:43:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/assistance-about-shared-interface-between-multiple-contexts/m-p/613761#M1023868</guid>
      <dc:creator>junzhang</dc:creator>
      <dc:date>2019-03-11T09:43:11Z</dc:date>
    </item>
    <item>
      <title>Re: Assistance about shared interface between multiple contexts</title>
      <link>https://community.cisco.com/t5/network-security/assistance-about-shared-interface-between-multiple-contexts/m-p/613762#M1023869</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It sounds like the classifier is having a problem in sending the traffic to the right context interface. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you say you have static NAT setup what do you mean ? On a shared vlan you must map NAT statements within each context and clearly between contexts you can't have any overlap. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you send the configs of your 2 contexts with an explanation of where you are connecting from and where you are connecting to and we might be able to help you. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Mar 2007 08:13:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/assistance-about-shared-interface-between-multiple-contexts/m-p/613762#M1023869</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-03-08T08:13:49Z</dc:date>
    </item>
    <item>
      <title>Re: Assistance about shared interface between multiple contexts</title>
      <link>https://community.cisco.com/t5/network-security/assistance-about-shared-interface-between-multiple-contexts/m-p/613763#M1023872</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your help. The mainly config of the 2 contexts are as the following.&lt;/P&gt;&lt;P&gt;No.1:&lt;/P&gt;&lt;P&gt;interface Vlan106&lt;/P&gt;&lt;P&gt; description Outside&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 10.0.9.1 255.255.255.192 standby 10.0.9.2 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan222&lt;/P&gt;&lt;P&gt; description Link-FW-ShiHou-CeShi_Server&lt;/P&gt;&lt;P&gt; nameif FW-ShiHou-CeShi_Server&lt;/P&gt;&lt;P&gt; security-level 70&lt;/P&gt;&lt;P&gt; ip address 10.0.22.254 255.255.255.0 standby 10.0.22.253 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-list any extended permit ip any any &lt;/P&gt;&lt;P&gt;access-list any extended permit icmp any any &lt;/P&gt;&lt;P&gt;access-list any extended permit tcp any any &lt;/P&gt;&lt;P&gt;access-list any extended permit tcp any any gt 1 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;icmp permit 10.0.9.0 255.255.255.0 outside&lt;/P&gt;&lt;P&gt;icmp permit 10.0.22.0 255.255.255.0 FW-ShiHou-CeShi_Server&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;nat (FW-ShiHou-CeShi_Server) 0 10.0.22.0 255.255.255.0&lt;/P&gt;&lt;P&gt;static (FW-ShiHou-CeShi_Server,outside) 10.0.22.0 10.0.22.0 netmask 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-group any in interface outside&lt;/P&gt;&lt;P&gt;access-group any out interface outside&lt;/P&gt;&lt;P&gt;access-group any in interface FW-ShiHou-CeShi_Server&lt;/P&gt;&lt;P&gt;access-group any out interface FW-ShiHou-CeShi_Server&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 10.0.9.5 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No.2:&lt;/P&gt;&lt;P&gt;interface Vlan105&lt;/P&gt;&lt;P&gt; description Network Manage Hosts&lt;/P&gt;&lt;P&gt; nameif netmanage&lt;/P&gt;&lt;P&gt; security-level 60&lt;/P&gt;&lt;P&gt; ip address 10.0.5.254 255.255.255.0 standby 10.0.5.253&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan222&lt;/P&gt;&lt;P&gt; description Link-FW-ShiHou-CeShi_Server&lt;/P&gt;&lt;P&gt; nameif FW-ShiHou-CeShi_Server&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.0.22.250 255.255.255.0 standby 10.0.22.249&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-list Netman extended permit ip 10.0.5.0 255.255.255.0 any &lt;/P&gt;&lt;P&gt;access-list Netman extended permit icmp 10.0.5.0 255.255.255.0 any &lt;/P&gt;&lt;P&gt;access-list Netman extended permit ip any 10.0.5.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list Netman extended permit icmp any 10.0.5.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-list CESHI extended permit ip 10.0.5.0 255.255.255.0 10.0.22.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list CESHI extended permit icmp 10.0.5.0 255.255.255.0 10.0.22.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list CESHI extended permit ip 10.0.22.0 255.255.255.0 10.0.5.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list CESHI extended permit icmp 10.0.22.0 255.255.255.0 10.0.5.0 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;static (FW-ShiHou-CeShi_Server,netmanage) 10.0.22.0 10.0.22.0 netmask 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-group Netman in interface netmanage&lt;/P&gt;&lt;P&gt;access-group CESHI in interface FW-ShiHou-CeShi_Server&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;icmp permit 10.0.5.0 255.255.255.0 netmanage&lt;/P&gt;&lt;P&gt;icmp permit 10.0.22.0 255.255.255.0 FW-ShiHou-CeShi_Server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, in the first context, all the traffic are normal.In the second context the icmp traffic from the 10.0.5.0 to the netmanage interface and from the 10.0.22.0 to the FW-ShiHou-CeShi_Server are normal. But the traffic go through the context from outside to inside is not work. And when I ping from 10.0.5.0 to 10.0.22.0 the xlate table in the 2nd. context have the right items but can not see any information although the context icmp debug is open.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your help!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ZJ&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Mar 2007 00:05:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/assistance-about-shared-interface-between-multiple-contexts/m-p/613763#M1023872</guid>
      <dc:creator>junzhang</dc:creator>
      <dc:date>2007-03-09T00:05:06Z</dc:date>
    </item>
    <item>
      <title>Re: Assistance about shared interface between multiple contexts</title>
      <link>https://community.cisco.com/t5/network-security/assistance-about-shared-interface-between-multiple-contexts/m-p/613764#M1023875</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apologies for the delay in replying, i've been off work for a couple of days. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you use shared interfaces you have to setup static NAT translations whether the traffic is coming from a higher to a lower level security interface or vice-versa. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You don't have a NAT translation in context 2 for the 10.0.5.0 network. I think when the icmp echo reply is sent from vlan 222 to the vlan 105 the FWSM does not know how to classify the traffic. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need a Nat statement for the 10.0.5.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;try &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (netmanage,FW-ShiHou-CeShi_Server) 10.0.5.0 10.0.5.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know how you get on &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Mar 2007 11:17:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/assistance-about-shared-interface-between-multiple-contexts/m-p/613764#M1023875</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-03-12T11:17:56Z</dc:date>
    </item>
  </channel>
</rss>

