<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic What code version are you in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-fwsm-enable-traffic-between-two-or-more-hosts-connected-to/m-p/2824467#M174564</link>
    <description>&lt;P&gt;What code version are you running on the FWSM ?&lt;/P&gt;
&lt;P&gt;What exactly is the problem with the static statements , do you just want to tidy up the configuration ?&lt;/P&gt;
&lt;P&gt;Jon&lt;/P&gt;</description>
    <pubDate>Wed, 25 Nov 2015 21:35:10 GMT</pubDate>
    <dc:creator>Jon Marshall</dc:creator>
    <dc:date>2015-11-25T21:35:10Z</dc:date>
    <item>
      <title>CISCO FWSM - Enable traffic between two or more hosts connected to the same interface</title>
      <link>https://community.cisco.com/t5/network-security/cisco-fwsm-enable-traffic-between-two-or-more-hosts-connected-to/m-p/2824460#M174557</link>
      <description>&lt;P&gt;Hi guys!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have a doubt here, I have a Cisco FWSM and I would like&amp;nbsp;to active the parameter&amp;nbsp;describe bellow:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;"Enable traffic between two or more hosts connected to the same interface"&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The motive to enable this is because I have many static rules without necessary like this:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;static (BASE-ADV,NET-INT) 10.37.0.0 10.37.0.0 netmask 255.255.255.0&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;My FWSM is in production at this time and I can't stop the service and I can't lost any rule there.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;What will happen when I active this parameter?&lt;/P&gt;
&lt;P&gt;What will happen with the statics rules after I active the parameter?&lt;/P&gt;
&lt;P&gt;Whats the risk&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you very much!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Anderson.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:56:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-fwsm-enable-traffic-between-two-or-more-hosts-connected-to/m-p/2824460#M174557</guid>
      <dc:creator>Anderson Ribeiro</dc:creator>
      <dc:date>2019-03-12T06:56:53Z</dc:date>
    </item>
    <item>
      <title>It's not clear how enabling</title>
      <link>https://community.cisco.com/t5/network-security/cisco-fwsm-enable-traffic-between-two-or-more-hosts-connected-to/m-p/2824461#M174558</link>
      <description>&lt;P&gt;It's not clear how enabling traffic between hosts connected to the same interface is related to your static NAT statement.&lt;/P&gt;
&lt;P&gt;The static NAT is for traffic between two different interfaces so how will enabling traffic between hosts on the same interface replace that static NAT.&lt;/P&gt;
&lt;P&gt;Can you clarify exactly what you are trying to do ?&lt;/P&gt;
&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2015 16:12:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-fwsm-enable-traffic-between-two-or-more-hosts-connected-to/m-p/2824461#M174558</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2015-11-25T16:12:56Z</dc:date>
    </item>
    <item>
      <title>Jon,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-fwsm-enable-traffic-between-two-or-more-hosts-connected-to/m-p/2824462#M174559</link>
      <description>&lt;P&gt;Jon,&lt;/P&gt;
&lt;P&gt;In this case is different, look:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;static (BASE-ADV,NET-INT) 10.37.0.0 10.37.0.0 netmask 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Interface BASE-ADV&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Interface NET-INT&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2015 17:24:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-fwsm-enable-traffic-between-two-or-more-hosts-connected-to/m-p/2824462#M174559</guid>
      <dc:creator>Anderson Ribeiro</dc:creator>
      <dc:date>2015-11-25T17:24:17Z</dc:date>
    </item>
    <item>
      <title>Yes, they are different</title>
      <link>https://community.cisco.com/t5/network-security/cisco-fwsm-enable-traffic-between-two-or-more-hosts-connected-to/m-p/2824463#M174560</link>
      <description>&lt;P&gt;Yes, they are different interfaces, that was my point.&lt;/P&gt;
&lt;P&gt;How does enabling traffic between hosts on the same interface having anything to do with traffic between different interfaces ?&lt;/P&gt;
&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2015 18:06:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-fwsm-enable-traffic-between-two-or-more-hosts-connected-to/m-p/2824463#M174560</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2015-11-25T18:06:29Z</dc:date>
    </item>
    <item>
      <title>For example, if I need create</title>
      <link>https://community.cisco.com/t5/network-security/cisco-fwsm-enable-traffic-between-two-or-more-hosts-connected-to/m-p/2824464#M174561</link>
      <description>&lt;P&gt;For example, if I need create the rule where the IP 10.10.10.10 (Interface ADV-X) connect to 20.20.20.20 (Interface ADV-Y), so I need do this:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;access-list ADV-X&amp;nbsp;extended permit ip any host 10.10.10.10 host 20.20.20.20&lt;/P&gt;
&lt;P&gt;static (ADV-Y,ADV-X) 20.20.20.20 20.20.20.20&amp;nbsp;netmask 255.255.255.255&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;What that I want to&amp;nbsp;do is not use the static line more. Use only "access-list".&lt;/P&gt;
&lt;P&gt;For this I enable the parameter "&lt;STRONG&gt;Enable traffic between two or more hosts connected to the same interface"&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Do you agree?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Tks!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2015 19:30:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-fwsm-enable-traffic-between-two-or-more-hosts-connected-to/m-p/2824464#M174561</guid>
      <dc:creator>Anderson Ribeiro</dc:creator>
      <dc:date>2015-11-25T19:30:02Z</dc:date>
    </item>
    <item>
      <title>No I don't agree because the</title>
      <link>https://community.cisco.com/t5/network-security/cisco-fwsm-enable-traffic-between-two-or-more-hosts-connected-to/m-p/2824465#M174562</link>
      <description>&lt;P&gt;No I don't agree because the example you gave is using two different interfaces.&lt;/P&gt;
&lt;P&gt;Jon&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2015 19:36:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-fwsm-enable-traffic-between-two-or-more-hosts-connected-to/m-p/2824465#M174562</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2015-11-25T19:36:02Z</dc:date>
    </item>
    <item>
      <title>Ok, sorry. I understood that</title>
      <link>https://community.cisco.com/t5/network-security/cisco-fwsm-enable-traffic-between-two-or-more-hosts-connected-to/m-p/2824466#M174563</link>
      <description>&lt;P&gt;Ok, sorry. I understood that I said.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;How you would to do &amp;nbsp;use only the acl in this case?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2015 20:20:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-fwsm-enable-traffic-between-two-or-more-hosts-connected-to/m-p/2824466#M174563</guid>
      <dc:creator>Anderson Ribeiro</dc:creator>
      <dc:date>2015-11-25T20:20:13Z</dc:date>
    </item>
    <item>
      <title>What code version are you</title>
      <link>https://community.cisco.com/t5/network-security/cisco-fwsm-enable-traffic-between-two-or-more-hosts-connected-to/m-p/2824467#M174564</link>
      <description>&lt;P&gt;What code version are you running on the FWSM ?&lt;/P&gt;
&lt;P&gt;What exactly is the problem with the static statements , do you just want to tidy up the configuration ?&lt;/P&gt;
&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2015 21:35:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-fwsm-enable-traffic-between-two-or-more-hosts-connected-to/m-p/2824467#M174564</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2015-11-25T21:35:10Z</dc:date>
    </item>
    <item>
      <title>FWSM Firewall Version 4.1(11)</title>
      <link>https://community.cisco.com/t5/network-security/cisco-fwsm-enable-traffic-between-two-or-more-hosts-connected-to/m-p/2824468#M174565</link>
      <description>&lt;P&gt;FWSM Firewall Version 4.1(11)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The problem is that I would like not use static rules when the rule is to same IP. I want to use only access-list in this case.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I saw in the documentation about &lt;STRONG&gt;"Static Identity NAT"&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;For example, I have the IP 10.10.10.10 in the interface LAN_X and I need permit this IP to connect the IP 20.20.20.20 in the interface DMZ in any port. How can I create this rule?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;Option 1:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;access-list LAN_X permit ip host 10.10.10.10 host 20.20.20.20&lt;/P&gt;
&lt;P&gt;static (DMZ,LAN_X) 20.20.20.20 20.20.20.20 netmask 255.255.255.255&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;Option 2 (That I want configure):&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;access-list LAN_X permit ip host 10.10.10.10 host 20.20.20.20&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;What that I need configure to not use static rule in cases that I have the same destination IP?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2015 10:41:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-fwsm-enable-traffic-between-two-or-more-hosts-connected-to/m-p/2824468#M174565</guid>
      <dc:creator>Anderson Ribeiro</dc:creator>
      <dc:date>2015-11-26T10:41:12Z</dc:date>
    </item>
  </channel>
</rss>

