<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FWSM configuration in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fwsm-configuration/m-p/1584975#M564642</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am new to FWSM and i have a network in which FWSM is installed on 7613 router which has many wan links connected to it,there is a P2P link between router and cisco 3560 G multilayer switch(10.229.1.252/30) ,this L3 has 4 vlans and other networks connected to L3 and another switch 3560&amp;nbsp; is connected to L3 which connects its own LAN in the range of 10.229.1.0/24.Should i use Transparent mode on FWSM&amp;nbsp; or Routed mode,what could be my inside and outside interface,and what ip adds should i use on them.Since its a connectivity based on Vlan interfaces should i use a new range for BV1 interface.&lt;/P&gt;&lt;P&gt;At present my topology is attached in Doc1 and current FWSM config in second attachment.,hope for your help in this case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;!--[if !mso]&gt;
&lt;style&gt;
v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-parent:"";
	mso-padding-alt:0cm 5.4pt 0cm 5.4pt;
	mso-para-margin:0cm;
	mso-para-margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:10.0pt;
	font-family:"Times New Roman";
	mso-fareast-font-family:"Times New Roman";
	mso-ansi-language:#0400;
	mso-fareast-language:#0400;
	mso-bidi-language:#0400;}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt; &lt;o:shapedefaults v:ext="edit" spidmax="1047"&gt;&lt;/o:shapedefaults&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt; &lt;o:shapelayout v:ext="edit"&gt; &lt;o:idmap v:ext="edit" data="1"&gt;&lt;/o:idmap&gt; &lt;/o:shapelayout&gt;&lt;/xml&gt;&lt;![endif]--&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;IMG height="396" src="https://community.cisco.com/" width="372" /&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 19:59:38 GMT</pubDate>
    <dc:creator>cisco.anubhav</dc:creator>
    <dc:date>2019-03-11T19:59:38Z</dc:date>
    <item>
      <title>FWSM configuration</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-configuration/m-p/1584975#M564642</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am new to FWSM and i have a network in which FWSM is installed on 7613 router which has many wan links connected to it,there is a P2P link between router and cisco 3560 G multilayer switch(10.229.1.252/30) ,this L3 has 4 vlans and other networks connected to L3 and another switch 3560&amp;nbsp; is connected to L3 which connects its own LAN in the range of 10.229.1.0/24.Should i use Transparent mode on FWSM&amp;nbsp; or Routed mode,what could be my inside and outside interface,and what ip adds should i use on them.Since its a connectivity based on Vlan interfaces should i use a new range for BV1 interface.&lt;/P&gt;&lt;P&gt;At present my topology is attached in Doc1 and current FWSM config in second attachment.,hope for your help in this case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;!--[if !mso]&gt;
&lt;style&gt;
v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-parent:"";
	mso-padding-alt:0cm 5.4pt 0cm 5.4pt;
	mso-para-margin:0cm;
	mso-para-margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:10.0pt;
	font-family:"Times New Roman";
	mso-fareast-font-family:"Times New Roman";
	mso-ansi-language:#0400;
	mso-fareast-language:#0400;
	mso-bidi-language:#0400;}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt; &lt;o:shapedefaults v:ext="edit" spidmax="1047"&gt;&lt;/o:shapedefaults&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt; &lt;o:shapelayout v:ext="edit"&gt; &lt;o:idmap v:ext="edit" data="1"&gt;&lt;/o:idmap&gt; &lt;/o:shapelayout&gt;&lt;/xml&gt;&lt;![endif]--&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;IMG height="396" src="https://community.cisco.com/" width="372" /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:59:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-configuration/m-p/1584975#M564642</guid>
      <dc:creator>cisco.anubhav</dc:creator>
      <dc:date>2019-03-11T19:59:38Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM configuration</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-configuration/m-p/1584976#M564645</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Conside which networks you want to protect and that way you will be able to set your inside and outside interfaces. I had a similar case and iI used bridge interfaces since I had multiple inside LAN subnets with different IPs as gateways on the core switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try to work your ideas, draw a topology and try to test this out before going into production.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Mar 2011 12:15:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-configuration/m-p/1584976#M564645</guid>
      <dc:creator>PAUL GILBERT ARIAS</dc:creator>
      <dc:date>2011-03-02T12:15:02Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM configuration</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-configuration/m-p/1584977#M564650</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply,its the ip that i m more concerned, what ip should i give on bv interface,as its said that both inside and outside sholud be on sane ip subnet and different vlan and inside interface must have the ip of the connected ip subnet.what ip should be used kindly suggest. kindly consider the attached config&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Mar 2011 13:14:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-configuration/m-p/1584977#M564650</guid>
      <dc:creator>cisco.anubhav</dc:creator>
      <dc:date>2011-03-02T13:14:01Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM configuration</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-configuration/m-p/1584978#M564655</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can add an available IP that could be reachable for management porpuses. If you are going to have bridge groups then it means that the firewall is in L2. If you are planning to have multiple bvi interface I can tell you it is not needed. You can create one just for management.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the setup I did for a costumer I configured the BVI interface in a complete different subnet, this was a management VLAN. Just make sure you include that VLAN on the configuration required on the 7600/6500.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Mar 2011 14:08:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-configuration/m-p/1584978#M564655</guid>
      <dc:creator>PAUL GILBERT ARIAS</dc:creator>
      <dc:date>2011-03-02T14:08:21Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM configuration</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-configuration/m-p/1584979#M564658</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for ur help,I m very cionfused at the moment so that&amp;nbsp; i may get out of this confusion.The scenario is this that FWSM is on cisco 7613 and my LAN to be protected is two swithches away there are point to point links between router and switchL3 using two ip adds 10.229.1.253.on router and 10.229.1.254 on switch what ip should we use on fwsm BV interface as curently we have put 10.229.1.252 on it but the status of BV interface is admin down and line protocol is up,&lt;/P&gt;&lt;P&gt;we have three vlan on our L3 and another switch connected to L3 has our Lans to be protected.Kindly help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Mar 2011 06:03:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-configuration/m-p/1584979#M564658</guid>
      <dc:creator>cisco.anubhav</dc:creator>
      <dc:date>2011-03-08T06:03:32Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM configuration</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-configuration/m-p/1584980#M564661</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Paul,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;kindly help and suggest if i m goin in the right direction,as there is a P2P link between my 7613 and L3 3560 and fwsm is on 7613 i m goin to use an entirely new address(say 192.168.1.0) for this192.168.1.1 will be on vlan 100 on router 1.2 will be on fwsm bv1 interface ,would it be okay as there are already 3 different VLANs on my L3 and one of them contains the servers i wanna protect(10.220.1.0 range).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Mar 2011 13:31:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-configuration/m-p/1584980#M564661</guid>
      <dc:creator>cisco.anubhav</dc:creator>
      <dc:date>2011-03-10T13:31:40Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM configuration</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-configuration/m-p/1584981#M564665</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;it the interface is admin down you need to apply the no shut command.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Mar 2011 14:13:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-configuration/m-p/1584981#M564665</guid>
      <dc:creator>PAUL GILBERT ARIAS</dc:creator>
      <dc:date>2011-03-10T14:13:03Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM configuration</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-configuration/m-p/1584982#M564666</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am not able to understand this question. I need to picture it on my mind but I can't image how is the topology. Can you explain a little more?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Mar 2011 14:14:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-configuration/m-p/1584982#M564666</guid>
      <dc:creator>PAUL GILBERT ARIAS</dc:creator>
      <dc:date>2011-03-10T14:14:18Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM configuration</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-configuration/m-p/1584983#M564668</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Paul,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the figure is given in the first post of mine,still ,i may give it here&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;7613----FWSM-------3560------3560-------|10.229.1.0 (n/w to be protected.)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Mar 2011 05:37:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-configuration/m-p/1584983#M564668</guid>
      <dc:creator>cisco.anubhav</dc:creator>
      <dc:date>2011-03-11T05:37:35Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM configuration</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-configuration/m-p/1584984#M564669</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;P&gt;Hi Paul,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the figure is given in the first post of mine,still ,i may give it here&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ------------------&lt;/P&gt;&lt;P&gt;7613----FWSM-------3560------3560-------|&lt;SPAN style="text-decoration: underline;"&gt;10.229.1.0 &lt;/SPAN&gt;(n/w to be protected.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;10.220.62.x/30&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.22062.Y/30&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Mar 2011 10:59:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-configuration/m-p/1584984#M564669</guid>
      <dc:creator>cisco.anubhav</dc:creator>
      <dc:date>2011-03-11T10:59:38Z</dc:date>
    </item>
  </channel>
</rss>

