<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FWSM initial config in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fwsm-initial-config/m-p/2703181#M193928</link>
    <description>&lt;P&gt;Hi.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I haven't worked too much with FWSM modules, so I have a few easy questions:&lt;/P&gt;&lt;P&gt;1)&amp;nbsp;What's the vlan-group? Which vlans should I include on this group? Every single vlan that will be crossing the FW?&lt;/P&gt;&lt;P&gt;2) Do I have to configure vlan group and a SVI before being able to session into the Firewall? Can I run "session slot X processor 1" without configuring anything on the 6500 before?&lt;/P&gt;&lt;P&gt;3) What could be the main reasons why I could get a timeout when trying to session into the FW?&lt;/P&gt;&lt;P&gt;Thanks!!&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 06:14:52 GMT</pubDate>
    <dc:creator>Soporteco</dc:creator>
    <dc:date>2019-03-12T06:14:52Z</dc:date>
    <item>
      <title>FWSM initial config</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-initial-config/m-p/2703181#M193928</link>
      <description>&lt;P&gt;Hi.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I haven't worked too much with FWSM modules, so I have a few easy questions:&lt;/P&gt;&lt;P&gt;1)&amp;nbsp;What's the vlan-group? Which vlans should I include on this group? Every single vlan that will be crossing the FW?&lt;/P&gt;&lt;P&gt;2) Do I have to configure vlan group and a SVI before being able to session into the Firewall? Can I run "session slot X processor 1" without configuring anything on the 6500 before?&lt;/P&gt;&lt;P&gt;3) What could be the main reasons why I could get a timeout when trying to session into the FW?&lt;/P&gt;&lt;P&gt;Thanks!!&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:14:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-initial-config/m-p/2703181#M193928</guid>
      <dc:creator>Soporteco</dc:creator>
      <dc:date>2019-03-12T06:14:52Z</dc:date>
    </item>
    <item>
      <title>1) What's the vlan-group?</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-initial-config/m-p/2703182#M193929</link>
      <description>&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;1)&amp;nbsp;What's the vlan-group? Which vlans should I include on this group? Every single vlan that will be crossing the FW?&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;The vlan-group command is used to group VLANs together and then reference that group when assigning VLANs to the FWSM module.&amp;nbsp; The VLANs you have in this group is really up to you.&amp;nbsp; The number of VLANs that you assign to the FWSM is up to you, but this is a very broad question as it goes into network design and then this will depend on your requirements.&amp;nbsp; Because of this I am going keep my suggestion short.&amp;nbsp; Configre VRFs on the 6500 to seperate the different security levels.&amp;nbsp; Networks that should be able to communicate with eachother freely should be placed in the same VRF.&amp;nbsp; Networks that should have restricted access between eachother should be placed in different VRFs.&amp;nbsp; Try to keep the number of VRFs to a minimum for ease of managment.&amp;nbsp; The ASA should have a VLAN interface for each VRF.&amp;nbsp; Set a default route on the 6500 for each VRF to point to their respective ASA IP.&amp;nbsp; &lt;U&gt;&lt;STRONG&gt;**This is just a suggestion and should be implemented at your own risk**&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;2) Do I have to configure vlan group and a SVI before being able to session into the Firewall? Can I run "session slot X processor 1" without configuring anything on the 6500 before?&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Yes, you need to assign VLANs to the FWSM so that the switch is able to communicate with the firewall.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;3) What could be the main reasons why I could get a timeout when trying to session into the FW?&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;See answer from question #2&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Sat, 11 Jul 2015 18:43:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-initial-config/m-p/2703182#M193929</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2015-07-11T18:43:26Z</dc:date>
    </item>
  </channel>
</rss>

