<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Need help configuring my FWSM. Adding an interface? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/need-help-configuring-my-fwsm-adding-an-interface/m-p/2140201#M358809</link>
    <description>&lt;P&gt;So we have an FWSM in our 6509 chassis.&amp;nbsp; It has an inside interface and an outside interface to the internet.&amp;nbsp; I would like to add an interface to the FWSM to route to other parts of our network.&amp;nbsp; I have added the interface I want and have given it an IP, it can ping the other firewalls on the same network/vlan.&amp;nbsp; This interface is going to be the main link between other network segments.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The way the firewall is configured now, there's no VLANs on it, I believe that is all done on the supervior, etc.&amp;nbsp; I created the vlan99 on the 6500, I tried both giving it an IP and also just creating the vlan and the interface vlan but I can't get traffic to route from that switch to the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically I want the inside network to route everything to the inside interface, then the firewall will route out my new interface to other network segments.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not sure what I'm missing but I need help with it, so if anyone has experience with the FWSM please chime in!&amp;nbsp; I believe the FWSM is configured correctly, but I think the issue might be with the switch getting the traffic to it, etc.&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 01:24:21 GMT</pubDate>
    <dc:creator>cshannahan</dc:creator>
    <dc:date>2019-03-12T01:24:21Z</dc:date>
    <item>
      <title>Need help configuring my FWSM. Adding an interface?</title>
      <link>https://community.cisco.com/t5/network-security/need-help-configuring-my-fwsm-adding-an-interface/m-p/2140201#M358809</link>
      <description>&lt;P&gt;So we have an FWSM in our 6509 chassis.&amp;nbsp; It has an inside interface and an outside interface to the internet.&amp;nbsp; I would like to add an interface to the FWSM to route to other parts of our network.&amp;nbsp; I have added the interface I want and have given it an IP, it can ping the other firewalls on the same network/vlan.&amp;nbsp; This interface is going to be the main link between other network segments.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The way the firewall is configured now, there's no VLANs on it, I believe that is all done on the supervior, etc.&amp;nbsp; I created the vlan99 on the 6500, I tried both giving it an IP and also just creating the vlan and the interface vlan but I can't get traffic to route from that switch to the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically I want the inside network to route everything to the inside interface, then the firewall will route out my new interface to other network segments.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not sure what I'm missing but I need help with it, so if anyone has experience with the FWSM please chime in!&amp;nbsp; I believe the FWSM is configured correctly, but I think the issue might be with the switch getting the traffic to it, etc.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:24:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-configuring-my-fwsm-adding-an-interface/m-p/2140201#M358809</guid>
      <dc:creator>cshannahan</dc:creator>
      <dc:date>2019-03-12T01:24:21Z</dc:date>
    </item>
    <item>
      <title>Need help configuring my FWSM. Adding an interface?</title>
      <link>https://community.cisco.com/t5/network-security/need-help-configuring-my-fwsm-adding-an-interface/m-p/2140202#M358812</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you share the FWSM configuration and the Switch Setup for the firewall and that vlan&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Apr 2013 20:45:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-configuring-my-fwsm-adding-an-interface/m-p/2140202#M358812</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-04-05T20:45:14Z</dc:date>
    </item>
    <item>
      <title>Re: Need help configuring my FWSM. Adding an interface?</title>
      <link>https://community.cisco.com/t5/network-security/need-help-configuring-my-fwsm-adding-an-interface/m-p/2140203#M358815</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think this is all of the info that pertains to this. Attached a logical drawing, inside and 6500 would be "inside networks" at the top.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;6500 Switch&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;firewall multiple-vlan-interfaces&lt;/P&gt;&lt;P&gt;firewall module 3 vlan-group 250&lt;/P&gt;&lt;P&gt;firewall vlan-group 250&amp;nbsp; 99,230,240,245,250&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Port-channel1&lt;/P&gt;&lt;P&gt; switchport&lt;/P&gt;&lt;P&gt; switchport trunk encapsulation dot1q&lt;/P&gt;&lt;P&gt; switchport trunk allowed vlan 10,47,99,100,230,240,245,250,260,600,610&lt;/P&gt;&lt;P&gt; switchport mode trunk&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet4/6&lt;/P&gt;&lt;P&gt; description CSP to Demarc&lt;/P&gt;&lt;P&gt; switchport&lt;/P&gt;&lt;P&gt; switchport access vlan 99&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet4/31&lt;/P&gt;&lt;P&gt; description FWSM PRIVATE&lt;/P&gt;&lt;P&gt; switchport&lt;/P&gt;&lt;P&gt; switchport access vlan 230&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet4/32&lt;/P&gt;&lt;P&gt; description Connection to Internet Switch Gi1/0/1&lt;/P&gt;&lt;P&gt; switchport&lt;/P&gt;&lt;P&gt; switchport access vlan 240&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan10&lt;/P&gt;&lt;P&gt; description ETHER_CHANNEL VLAN&lt;/P&gt;&lt;P&gt; ip address 10.1.0.233 255.255.255.252&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan99&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan230&lt;/P&gt;&lt;P&gt; description FW-PRIVATE&lt;/P&gt;&lt;P&gt; ip address 10.47.2.3 255.255.255.0&lt;/P&gt;&lt;P&gt; standby 1 ip 10.47.2.5&lt;/P&gt;&lt;P&gt; standby 1 priority 125&lt;/P&gt;&lt;P&gt; standby 1 preempt&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan240&lt;/P&gt;&lt;P&gt; description FW-PUBLIC&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;router eigrp 1&lt;/P&gt;&lt;P&gt; network 10.47.47.0 0.0.0.15&lt;/P&gt;&lt;P&gt; network 10.0.0.0&lt;/P&gt;&lt;P&gt; no auto-summary&lt;/P&gt;&lt;P&gt; redistribute static&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip classless&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 10.47.2.1(INSIDE ADDRESS FWSM)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;FWSM&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan99&lt;/P&gt;&lt;P&gt; description Connection to Inland and Contractor Networks&lt;/P&gt;&lt;P&gt; nameif CSP&lt;/P&gt;&lt;P&gt; security-level 10&lt;/P&gt;&lt;P&gt; ip address 10.99.99.10 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan230&lt;/P&gt;&lt;P&gt; description FW-PRIVATE&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.47.2.1 255.255.255.0 standby 10.47.2.2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan240&lt;/P&gt;&lt;P&gt; description FW-PUBLIC&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address *.*.*.* standby *.*.*.*&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan250&lt;/P&gt;&lt;P&gt; description LAN/STATE Failover Interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip verify reverse-path interface inside&lt;/P&gt;&lt;P&gt;ip verify reverse-path interface outside&lt;/P&gt;&lt;P&gt;ip verify reverse-path interface CSP&lt;/P&gt;&lt;P&gt;failover&lt;/P&gt;&lt;P&gt;failover lan unit primary&lt;/P&gt;&lt;P&gt;failover lan interface FAILOVER Vlan250&lt;/P&gt;&lt;P&gt;failover replication http&lt;/P&gt;&lt;P&gt;failover link FAILOVER Vlan250&lt;/P&gt;&lt;P&gt;failover interface ip FAILOVER 10.1.0.237 255.255.255.252 standby 10.1.0.238&lt;/P&gt;&lt;P&gt;monitor-interface inside&lt;/P&gt;&lt;P&gt;monitor-interface outside&lt;/P&gt;&lt;P&gt;icmp permit any inside&lt;/P&gt;&lt;P&gt;icmp permit any outside&lt;/P&gt;&lt;P&gt;asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;nat-control&lt;/P&gt;&lt;P&gt;global (outside) 2 *.*.*.*netmask 255.255.255.240&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 2 access-list inside_nat_outbound&lt;/P&gt;&lt;P&gt;nat (inside) 1 10.0.0.0 255.0.0.0&lt;/P&gt;&lt;P&gt;access-group internet2 in interface inside&lt;/P&gt;&lt;P&gt;access-group internet1 in interface outside&lt;/P&gt;&lt;P&gt;access-group CSP_access_in in interface CSP&lt;/P&gt;&lt;P&gt;route inside 192.168.144.0 255.255.252.0 10.47.2.5 1&lt;/P&gt;&lt;P&gt;route inside 172.16.206.0 255.255.254.0 10.47.2.5 1&lt;/P&gt;&lt;P&gt;route inside 10.0.0.0 255.0.0.0 10.47.2.5 1&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 209.115.188.49 1&lt;/P&gt;&lt;P&gt;route CSP 10.5.2.0 255.255.255.0 10.99.99.20 1&lt;/P&gt;&lt;P&gt;route CSP 10.5.3.0 255.255.255.0 10.99.99.20 1&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Apr 2013 20:54:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-configuring-my-fwsm-adding-an-interface/m-p/2140203#M358815</guid>
      <dc:creator>cshannahan</dc:creator>
      <dc:date>2013-04-05T20:54:22Z</dc:date>
    </item>
    <item>
      <title>Need help configuring my FWSM. Adding an interface?</title>
      <link>https://community.cisco.com/t5/network-security/need-help-configuring-my-fwsm-adding-an-interface/m-p/2140204#M358817</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Okay let me analize this but may I know which is the new interface??&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Apr 2013 21:15:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-configuring-my-fwsm-adding-an-interface/m-p/2140204#M358817</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-04-05T21:15:18Z</dc:date>
    </item>
    <item>
      <title>Re: Need help configuring my FWSM. Adding an interface?</title>
      <link>https://community.cisco.com/t5/network-security/need-help-configuring-my-fwsm-adding-an-interface/m-p/2140205#M358819</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The CSP (vlan99) is the new interface, joining to the other networks/firewalls.&amp;nbsp; Added a diagram to above.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently the inside network 10.47.2.x and outside on the FWSM work fine, just trying to add this other function so we can talk to other parts of our network, etc.&amp;nbsp; That was all here before I started this job so I never had to do much to the FWSM. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm great with ASAs but when it comes to configuring the 6500/FWSM together I can't seem to get it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried giving vlan99 an IP on the 6500 as well, but when I do that it seems to bypass the firewall and just talk over layer 2.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Apr 2013 21:18:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-configuring-my-fwsm-adding-an-interface/m-p/2140205#M358819</guid>
      <dc:creator>cshannahan</dc:creator>
      <dc:date>2013-04-05T21:18:28Z</dc:date>
    </item>
    <item>
      <title>Re: Need help configuring my FWSM. Adding an interface?</title>
      <link>https://community.cisco.com/t5/network-security/need-help-configuring-my-fwsm-adding-an-interface/m-p/2140206#M358821</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I tried giving vlan99 an IP on the 6500 as well, but when I do that it seems to bypass the firewall and just talk over layer 2.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Exactly, that will bypass the FWSM&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have nat-control On so you neet a NAT statement for the new interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (&lt;SPAN style="font-size: 10pt;"&gt;CSP) 1 0 0 &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;From the FWSM can you ping &lt;SPAN style="font-size: 10pt;"&gt;10.99.99.20 ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Apr 2013 21:25:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-configuring-my-fwsm-adding-an-interface/m-p/2140206#M358821</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-04-05T21:25:43Z</dc:date>
    </item>
    <item>
      <title>Re: Need help configuring my FWSM. Adding an interface?</title>
      <link>https://community.cisco.com/t5/network-security/need-help-configuring-my-fwsm-adding-an-interface/m-p/2140207#M358822</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Exactly, when I give vlan99 an IP it seems to bypass.&amp;nbsp; From the FWSM I can ping .20 and .30.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I try to ping or access anything outside of the 6500 I don't see it getting to the firewall.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Apr 2013 21:32:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-configuring-my-fwsm-adding-an-interface/m-p/2140207#M358822</guid>
      <dc:creator>cshannahan</dc:creator>
      <dc:date>2013-04-05T21:32:58Z</dc:date>
    </item>
    <item>
      <title>Re: Need help configuring my FWSM. Adding an interface?</title>
      <link>https://community.cisco.com/t5/network-security/need-help-configuring-my-fwsm-adding-an-interface/m-p/2140208#M358823</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can you do a capture on the Inside interface of the FWSM to check if we are getting the packets there?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Apr 2013 21:38:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-configuring-my-fwsm-adding-an-interface/m-p/2140208#M358823</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-04-05T21:38:05Z</dc:date>
    </item>
    <item>
      <title>Re: Need help configuring my FWSM. Adding an interface?</title>
      <link>https://community.cisco.com/t5/network-security/need-help-configuring-my-fwsm-adding-an-interface/m-p/2140209#M358824</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where are you testing the traffic from (source IP) and to where are you testing the traffic to (destination IP)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you also show what your routing table looks like on the 6500?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You seem to have the current interfaces in the Global Routing Table which means those networks see eachother even without the FWSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Typically in our FWSM enviroments we configure each network segment and its Vlan interfaces to their own VRF which means their networks/routing is separated to their own virtual routing table.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But to be honest, I am not totally sure between which networks you have done tests currently that fail?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Apr 2013 21:58:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-configuring-my-fwsm-adding-an-interface/m-p/2140209#M358824</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-04-05T21:58:52Z</dc:date>
    </item>
    <item>
      <title>Re: Need help configuring my FWSM. Adding an interface?</title>
      <link>https://community.cisco.com/t5/network-security/need-help-configuring-my-fwsm-adding-an-interface/m-p/2140210#M358826</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've been trying just from the 6500 itself with pings.&amp;nbsp; I can try from a server on the 10.47.2.x network as well.&amp;nbsp; Basically trying to ping anything on my 10.99.99.x network or even the 10.5.2.x network which I've allowed ping through.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried a capture, didn't seem to work, must have set it up wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Routing table is up top, default route is what should be used...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Apr 2013 22:01:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-configuring-my-fwsm-adding-an-interface/m-p/2140210#M358826</guid>
      <dc:creator>cshannahan</dc:creator>
      <dc:date>2013-04-05T22:01:25Z</dc:date>
    </item>
    <item>
      <title>Re: Need help configuring my FWSM. Adding an interface?</title>
      <link>https://community.cisco.com/t5/network-security/need-help-configuring-my-fwsm-adding-an-interface/m-p/2140211#M358827</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Okay,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the Catalyst we only need the SVI for the Inside interface, the other 2 just basic layer 2 Vlans and that's it..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are sending all the traffic to the FWSM via the inside interface, that's why I asked for the capture,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if you see something as soon as you set it properly &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Apr 2013 22:43:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-configuring-my-fwsm-adding-an-interface/m-p/2140211#M358827</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-04-05T22:43:09Z</dc:date>
    </item>
    <item>
      <title>Re: Need help configuring my FWSM. Adding an interface?</title>
      <link>https://community.cisco.com/t5/network-security/need-help-configuring-my-fwsm-adding-an-interface/m-p/2140212#M358828</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The inside interface works, and we have the vlan 230 with an address there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;interface Vlan230&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;description FW-PRIVATE&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;ip address 10.47.2.3 255.255.255.0&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;standby 1 ip 10.47.2.5&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;standby 1 priority 125&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;standby 1 preempt&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried the capture but it didn't work so I will have to find out what I'm doing wrong.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Apr 2013 23:04:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-configuring-my-fwsm-adding-an-interface/m-p/2140212#M358828</guid>
      <dc:creator>cshannahan</dc:creator>
      <dc:date>2013-04-05T23:04:42Z</dc:date>
    </item>
    <item>
      <title>Re: Need help configuring my FWSM. Adding an interface?</title>
      <link>https://community.cisco.com/t5/network-security/need-help-configuring-my-fwsm-adding-an-interface/m-p/2140213#M358829</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's a shame we do not have the packet-tracer command on the FWSM family.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,&lt;SPAN style="font-size: 10pt;"&gt;CSP)&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;10.47.2.0 &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;10.47.2.10&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;static (CSP,inside) &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;10.99.99.0 10.99.99.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From a PC withing the new vlan, can you try to ping a host on the inside ( use a host different than the 10.47.2.1 and .2 as those are used by the FWSM)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then create this capture&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list test match icmp host CSP_IP_address host Inside_address_ip&lt;/P&gt;&lt;P&gt;capture test interface CSP access-list test&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then ping and share &lt;/P&gt;&lt;P&gt;Show cap test &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio carvajal &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Apr 2013 23:19:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-configuring-my-fwsm-adding-an-interface/m-p/2140213#M358829</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-04-05T23:19:49Z</dc:date>
    </item>
    <item>
      <title>Need help configuring my FWSM. Adding an interface?</title>
      <link>https://community.cisco.com/t5/network-security/need-help-configuring-my-fwsm-adding-an-interface/m-p/2140214#M358830</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If I make the inside interfaces and the CSP interfaces all the same security, I shouldn't need the statics correct?&amp;nbsp; I just made them all 100 for now.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 07 Apr 2013 13:18:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-configuring-my-fwsm-adding-an-interface/m-p/2140214#M358830</guid>
      <dc:creator>cshannahan</dc:creator>
      <dc:date>2013-04-07T13:18:29Z</dc:date>
    </item>
    <item>
      <title>Need help configuring my FWSM. Adding an interface?</title>
      <link>https://community.cisco.com/t5/network-security/need-help-configuring-my-fwsm-adding-an-interface/m-p/2140215#M358831</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is absolutly stupid.&amp;nbsp; I'm not sure why they can't just make a command that forces an interface on the 6500 to be a firewalled interface.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I ping from a host 10.47.2.6 to 10.99.99.20 it works but again just over layer 2.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 07 Apr 2013 14:43:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-configuring-my-fwsm-adding-an-interface/m-p/2140215#M358831</guid>
      <dc:creator>cshannahan</dc:creator>
      <dc:date>2013-04-07T14:43:43Z</dc:date>
    </item>
    <item>
      <title>Need help configuring my FWSM. Adding an interface?</title>
      <link>https://community.cisco.com/t5/network-security/need-help-configuring-my-fwsm-adding-an-interface/m-p/2140216#M358832</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok progress.&amp;nbsp; Although I removed the interface vlan 99 info, the actual interface vlan 99 was still there on the MFSC, so I removed that, added some NAT statements and now I'm getting from inside the FWSM to inside the firewall on the other side so I think once I get all of the nat statements sorted out I should be working without issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 07 Apr 2013 16:38:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-configuring-my-fwsm-adding-an-interface/m-p/2140216#M358832</guid>
      <dc:creator>cshannahan</dc:creator>
      <dc:date>2013-04-07T16:38:26Z</dc:date>
    </item>
  </channel>
</rss>

