<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VM environment and Firewall in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/vm-environment-and-firewall/m-p/1557245#M600554</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sure thing&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have a virtual cluster&lt;/P&gt;&lt;P&gt;and currently a single esx host connected to a&lt;/P&gt;&lt;P&gt;physical cisco switch then from the switch to the firewall.&lt;/P&gt;&lt;P&gt;the firewall has 3 interfaces for 3 different networks&lt;/P&gt;&lt;P&gt;10.0.20.0/24, 10.0.30.0/24 and 10.0.40.0/24&lt;/P&gt;&lt;P&gt;which are going to simulate INT, EXT, and DMZ&lt;/P&gt;&lt;P&gt;the switch has the routing disabled and configured&lt;/P&gt;&lt;P&gt;on trunk port from the vm environment and the 3 ports&lt;/P&gt;&lt;P&gt;with the different vlan for the 3 different networks.&lt;/P&gt;&lt;P&gt;either I can ping everything with ICMP being permitted&lt;/P&gt;&lt;P&gt;or I can't ping anything with it being blocked.&lt;/P&gt;&lt;P&gt;vlan's have an ip of .1 firewall interfaces have an ip of .2&lt;/P&gt;&lt;P&gt;and each test system has an ip of .3. I am trying to get a basic&lt;/P&gt;&lt;P&gt;firewall config to allow all outbound from INT to pass and DMZ to gout but not in&lt;/P&gt;&lt;P&gt;and nothing to come in from EXT. Also can anyone explain to me why a switch needs a default gateway when ip routing is disabled?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 20 Oct 2010 15:52:22 GMT</pubDate>
    <dc:creator>eduardo.aquino</dc:creator>
    <dc:date>2010-10-20T15:52:22Z</dc:date>
    <item>
      <title>VM environment and Firewall</title>
      <link>https://community.cisco.com/t5/network-security/vm-environment-and-firewall/m-p/1557243#M600552</link>
      <description>&lt;P&gt;We have a vm environment and then a physical switch and a firewall&lt;/P&gt;&lt;P&gt;can't seem to get it to work&lt;/P&gt;&lt;P&gt;need some assistance and I am trying to learn what is going on&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:57:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vm-environment-and-firewall/m-p/1557243#M600552</guid>
      <dc:creator>eduardo.aquino</dc:creator>
      <dc:date>2019-03-11T18:57:26Z</dc:date>
    </item>
    <item>
      <title>Re: VM environment and Firewall</title>
      <link>https://community.cisco.com/t5/network-security/vm-environment-and-firewall/m-p/1557244#M600553</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Eduardo,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Start with bascis - topology diagram and IP schema. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is working, what is not working (pings, http, dns?)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marcin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Oct 2010 15:07:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vm-environment-and-firewall/m-p/1557244#M600553</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2010-10-20T15:07:29Z</dc:date>
    </item>
    <item>
      <title>Re: VM environment and Firewall</title>
      <link>https://community.cisco.com/t5/network-security/vm-environment-and-firewall/m-p/1557245#M600554</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sure thing&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have a virtual cluster&lt;/P&gt;&lt;P&gt;and currently a single esx host connected to a&lt;/P&gt;&lt;P&gt;physical cisco switch then from the switch to the firewall.&lt;/P&gt;&lt;P&gt;the firewall has 3 interfaces for 3 different networks&lt;/P&gt;&lt;P&gt;10.0.20.0/24, 10.0.30.0/24 and 10.0.40.0/24&lt;/P&gt;&lt;P&gt;which are going to simulate INT, EXT, and DMZ&lt;/P&gt;&lt;P&gt;the switch has the routing disabled and configured&lt;/P&gt;&lt;P&gt;on trunk port from the vm environment and the 3 ports&lt;/P&gt;&lt;P&gt;with the different vlan for the 3 different networks.&lt;/P&gt;&lt;P&gt;either I can ping everything with ICMP being permitted&lt;/P&gt;&lt;P&gt;or I can't ping anything with it being blocked.&lt;/P&gt;&lt;P&gt;vlan's have an ip of .1 firewall interfaces have an ip of .2&lt;/P&gt;&lt;P&gt;and each test system has an ip of .3. I am trying to get a basic&lt;/P&gt;&lt;P&gt;firewall config to allow all outbound from INT to pass and DMZ to gout but not in&lt;/P&gt;&lt;P&gt;and nothing to come in from EXT. Also can anyone explain to me why a switch needs a default gateway when ip routing is disabled?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Oct 2010 15:52:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vm-environment-and-firewall/m-p/1557245#M600554</guid>
      <dc:creator>eduardo.aquino</dc:creator>
      <dc:date>2010-10-20T15:52:22Z</dc:date>
    </item>
    <item>
      <title>Re: VM environment and Firewall</title>
      <link>https://community.cisco.com/t5/network-security/vm-environment-and-firewall/m-p/1557246#M600555</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Eduardo,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip default-gateway is used to manage switch, it's not there for routing of packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you attach "show run" from ASA and enable logging on informational level to buffer, do the test and extract "show logg" output?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;----------&lt;/P&gt;&lt;P&gt;logg on&lt;/P&gt;&lt;P&gt;logg buffered info&lt;/P&gt;&lt;P&gt;logg buffer-size 1000000&lt;/P&gt;&lt;P&gt;----------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the output of "show logg" is too big you can tailor it by doing "show logg | i IP_ADDR"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marcin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Oct 2010 16:00:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vm-environment-and-firewall/m-p/1557246#M600555</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2010-10-20T16:00:11Z</dc:date>
    </item>
    <item>
      <title>Re: VM environment and Firewall</title>
      <link>https://community.cisco.com/t5/network-security/vm-environment-and-firewall/m-p/1557247#M600556</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok&lt;/P&gt;&lt;P&gt;I'll work on getting you the config and the buffer/log info&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And what do you mean its for managing switch.&lt;/P&gt;&lt;P&gt;because i am being told that it directing traffic&lt;/P&gt;&lt;P&gt;on the gateway&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Oct 2010 16:28:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vm-environment-and-firewall/m-p/1557247#M600556</guid>
      <dc:creator>eduardo.aquino</dc:creator>
      <dc:date>2010-10-20T16:28:04Z</dc:date>
    </item>
    <item>
      <title>Re: VM environment and Firewall</title>
      <link>https://community.cisco.com/t5/network-security/vm-environment-and-firewall/m-p/1557248#M600557</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regular packets from a host going to the internet are not going to be routed using that default gateway. That default gateway will be used if you are doing telnet to the switch from a subnet that is not the same as the switch is located, the telnet replies to the default gateway address. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will be waiting for the config and the logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Oct 2010 21:42:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vm-environment-and-firewall/m-p/1557248#M600557</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2010-10-20T21:42:05Z</dc:date>
    </item>
  </channel>
</rss>

