<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FWSM single mode vs Multi mode in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fwsm-single-mode-vs-multi-mode/m-p/658130#M1028441</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mike &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes you can have multiple DMZ interfaces off each context. Had a quick check and it's 256 per context in routed mode. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 23 Jan 2007 15:40:20 GMT</pubDate>
    <dc:creator>Jon Marshall</dc:creator>
    <dc:date>2007-01-23T15:40:20Z</dc:date>
    <item>
      <title>FWSM single mode vs Multi mode</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-single-mode-vs-multi-mode/m-p/658125#M1028436</link>
      <description>&lt;P&gt;I'm trying to find information comparing the two modes to decide which is the best fit for my company... Can anyone point me in the right direction?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:22:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-single-mode-vs-multi-mode/m-p/658125#M1028436</guid>
      <dc:creator>MICHAEL CICCONE</dc:creator>
      <dc:date>2019-03-11T09:22:16Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM single mode vs Multi mode</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-single-mode-vs-multi-mode/m-p/658126#M1028437</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It really depends on what you are trying to achieve with your firewalls. &lt;/P&gt;&lt;P&gt;Multi mode is useful if you have service provider type setup where you can allocate a context to each customer and give them control of their own virtual firewall. It can also be useful if you have different depts. within your company which are responsible for their own security. &lt;/P&gt;&lt;P&gt;Having said that we use multi contexts on our firewalls in our datacentre. It allows us to segregate the firewalls based on server function which makes the access-lists more manageable and we can also create a context on the firewall which maps to a context on our ACE blades. &lt;/P&gt;&lt;P&gt;There are however some downsides to using multi context which may or may not be an issue for you. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) The context licenses themselves are not cheap as you are in effect buying multiple firewalls. &lt;/P&gt;&lt;P&gt;2) You cannot run a routing protocol on the FWSM's. In single mode you can use RIP or OSPF on the FWSM's but in multi mode you can only use static routing. &lt;/P&gt;&lt;P&gt;3) We are currently running v2.3 on our FWSM's which means you cannot have a mixture of routed vs transparent contexts. I believe this restriction has been lifted on v3.1 but it's worth checking. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Overall i'm comfortable with the decision we made and haven't found any of the restrictions too onerous. What i would suggest is that you work out how much firewalling you are actually going to be doing in terms of access-lists, statics etc, who needs access to the firewall (is it under single management or not) and if you are planning to deploy any of the other sevice modules. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any further questions let me know &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Jan 2007 12:03:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-single-mode-vs-multi-mode/m-p/658126#M1028437</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-01-20T12:03:22Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM single mode vs Multi mode</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-single-mode-vs-multi-mode/m-p/658127#M1028438</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Thanks for the answers.  I do have another question.  When you run FWSM in single mode you can create x number of virtual firewalls correct?  If that is true then I can create different access-lists for each virutal firewall?  I like the idea of segregating my servers via virtual firewalls.  For example, Webservers, applications servers and DB Servers.  I Would want to have them on different firewalls (virtually) from each other.  Can I do this in single mode?  &lt;/P&gt;&lt;P&gt;BTW:  Management will be done with a single person me, (the green guy :-))&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jan 2007 15:32:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-single-mode-vs-multi-mode/m-p/658127#M1028438</guid>
      <dc:creator>MICHAEL CICCONE</dc:creator>
      <dc:date>2007-01-22T15:32:58Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM single mode vs Multi mode</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-single-mode-vs-multi-mode/m-p/658128#M1028439</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can only create multiple virtual firewalls when your run the FWSM in multi-context mode. &lt;/P&gt;&lt;P&gt;In single mode the FWSM is just one big firewall with multiple DMZ interfaces (up to 256 If memory servers me right). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You do get 3 contexts with the default license 1 admin context + 2 others. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you need more you have to buy virtual context licenses and they are not cheap. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jan 2007 16:00:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-single-mode-vs-multi-mode/m-p/658128#M1028439</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-01-22T16:00:48Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM single mode vs Multi mode</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-single-mode-vs-multi-mode/m-p/658129#M1028440</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So, with 1 admin and 2 other contexts, Can I have multiple DMZ interfaces off of each context?&lt;/P&gt;&lt;P&gt;Again, Thanks for the help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jan 2007 20:31:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-single-mode-vs-multi-mode/m-p/658129#M1028440</guid>
      <dc:creator>MICHAEL CICCONE</dc:creator>
      <dc:date>2007-01-22T20:31:09Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM single mode vs Multi mode</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-single-mode-vs-multi-mode/m-p/658130#M1028441</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mike &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes you can have multiple DMZ interfaces off each context. Had a quick check and it's 256 per context in routed mode. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Jan 2007 15:40:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-single-mode-vs-multi-mode/m-p/658130#M1028441</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-01-23T15:40:20Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM single mode vs Multi mode</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-single-mode-vs-multi-mode/m-p/658131#M1028442</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Thanks for all the help... That answer some troubling questions for me&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Jan 2007 15:45:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-single-mode-vs-multi-mode/m-p/658131#M1028442</guid>
      <dc:creator>MICHAEL CICCONE</dc:creator>
      <dc:date>2007-01-23T15:45:55Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM single mode vs Multi mode</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-single-mode-vs-multi-mode/m-p/658132#M1028443</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No problem Mike. Thanks for using the rating system. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Jan 2007 15:51:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-single-mode-vs-multi-mode/m-p/658132#M1028443</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-01-23T15:51:04Z</dc:date>
    </item>
  </channel>
</rss>

