<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FWSM Incoming Traffic on inside Interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fwsm-incoming-traffic-on-inside-interface/m-p/1578746#M603046</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Breaking my admin &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 21 Sep 2010 17:28:38 GMT</pubDate>
    <dc:creator>Ian Beck</dc:creator>
    <dc:date>2010-09-21T17:28:38Z</dc:date>
    <item>
      <title>FWSM Incoming Traffic on inside Interface</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-incoming-traffic-on-inside-interface/m-p/1578733#M603030</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a FWSM ruuning on a 6509 with MFSC in context mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I configure up a full SVI routed environment on the MFSC to send packets to the FWSM it all works fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Howvever if I just have a VLAN to which my incoming traffic comes via a port on the switch and is routed from an attached router device connected to the switch port in the same VLAN directing traffic to the FWSM however I see no traffic crossing the Interface. I can ping from the router on the port to the FWSM ip address and the other way.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the Admin context works fine of the same VLAN !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas what I have missed&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 00:45:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-incoming-traffic-on-inside-interface/m-p/1578733#M603030</guid>
      <dc:creator>Ian Beck</dc:creator>
      <dc:date>2019-03-26T00:45:14Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM Incoming Traffic on inside Interface</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-incoming-traffic-on-inside-interface/m-p/1578734#M603031</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ian,&lt;/P&gt;&lt;P&gt;I am not sure if I follow you. Would you be able to add a simple text based topology?&lt;/P&gt;&lt;P&gt;You are sharing a vlan between two contexts?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Sep 2010 13:31:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-incoming-traffic-on-inside-interface/m-p/1578734#M603031</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-09-21T13:31:35Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM Incoming Traffic on inside Interface</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-incoming-traffic-on-inside-interface/m-p/1578735#M603032</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ian,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; There are two ways to firewall traffic with an FWSM:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) FWSM in routed mode:&lt;/P&gt;&lt;P&gt;You must route the traffic to the IP addresses of the FWSM as tho it was any other layer-3 hop in your network. This involves static routes or some routing protocol and results in traffic being routed to one interface of the FWSM and then the FWSM routes the traffic out another interface on the path to the destination.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) FWSM in transparent mode:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; For this to work you must break-up a layer-3 segment into two VLANs and assign one to either side of the FWSM. This does not invlove 'routing' the traffic to the FWSM with static routes or routing protocol. The trafic passes through the FWSM as tho the FWSM was a 'bump in the wire'.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What method are you intending for this to work, and how is it currently configured. Is the FWSM (context) transparent or routed?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Magnus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Sep 2010 14:14:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-incoming-traffic-on-inside-interface/m-p/1578735#M603032</guid>
      <dc:creator>Magnus Mortensen</dc:creator>
      <dc:date>2010-09-21T14:14:32Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM Incoming Traffic on inside Interface</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-incoming-traffic-on-inside-interface/m-p/1578736#M603034</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ian,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As KS had said, a text-based topology would be great.&amp;nbsp; My guess based strictly on your problem description is that you are likely hitting an asymmetric route situation. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In a routed network, the next Layer-3 device will make the next route decision.&amp;nbsp; If you have a complete SVI network configured on your switch, and you use these SVIs as the Default Gateway for the upstream routers/hosts, the Switch will make the next route decision. You can ping the local (ie same subnet) IP addresses as local subnet traffic is managed via ARP Requests/Responses. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, if traffic resides outside of the local subnet, the traffic is sent to the Default Gateway - the Default Gateway will make the next routing decision.&amp;nbsp; Since it is a fully-meshed SVI network on the Switch, it will likely have an entry in its routing table for the destination IP address that does NOT involve going through the FWSM. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want traffic to go through the FWSM, the key takeaway would be to use the FWSM's IP address as the next hop gateway for all of your upstream Layer-3 devices.&amp;nbsp; The other approach - leveraging a number of different SVIs on the Switch - often requires a significant effort to "work around" the FWSM.&amp;nbsp; This can be done, but it would require either route-maps and/or VRFs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this addresses your questions, please mark this question as answered for the benefit of others.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Kevin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Sep 2010 14:17:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-incoming-traffic-on-inside-interface/m-p/1578736#M603034</guid>
      <dc:creator>Kevin Redmon</dc:creator>
      <dc:date>2010-09-21T14:17:10Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM Incoming Traffic on inside Interface</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-incoming-traffic-on-inside-interface/m-p/1578737#M603036</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The FWSM is running in Routed mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have attached a diagram set which hopefully explians the issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Sep 2010 15:53:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-incoming-traffic-on-inside-interface/m-p/1578737#M603036</guid>
      <dc:creator>Ian Beck</dc:creator>
      <dc:date>2010-09-21T15:53:31Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM Incoming Traffic on inside Interface</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-incoming-traffic-on-inside-interface/m-p/1578738#M603038</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ian,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please provide us the flow that is/isn't working in the two scenarios below?&amp;nbsp; In particular, what is the source/destination IP address and VLAN.&amp;nbsp; Also, what is the difference in the routing tables between the non-working and the working scenario?&amp;nbsp; Make sure that the hop-by-hop routing makes sense for the flow and is what you would expect - both the forward and reverse flows must pass through the FWSM.&amp;nbsp; As in my previous post, if the next-hop is the 6500, you will need to check the 6500 route tables for the next routing decision.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have any syslogs at the time of the issue from the FWSM, that is also greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Kevin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Sep 2010 16:24:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-incoming-traffic-on-inside-interface/m-p/1578738#M603038</guid>
      <dc:creator>Kevin Redmon</dc:creator>
      <dc:date>2010-09-21T16:24:07Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM Incoming Traffic on inside Interface</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-incoming-traffic-on-inside-interface/m-p/1578739#M603039</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only difference betwen the to options is, the working one uses a SVI on the 6500 betwen two vlans and has all the correct routing, but is an over engineer solution, but it works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The none working solution, is purley a layer 2 VLAN no routing on the MFSC, all the routing is correct and all relevant traffic is routed correctly to the inside context IP Address and I have gone over it several times to check it all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically, the Gateway at the top points a route to the Firewall Interface and a relevant route on the firewall points at the Gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As I stated earlier, I can ping between the Gateway and FW no issue "permited ICMP", however when I send a simple ssh connection (the rule base is unchanged to the working version) to one of the Servers I do not get connected. I have tried denying very thing to get information in the Real Time Log of packets being denied or getting a No route statement. But I see nothing. On the Server side, as we are going to be using SSO I see all the traffic from the Server tying to talk to the AD Servers, but I am not sure they get answered (I have not investigated it)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I even tried a traffic capture but all I saw was the SYN packet and nothing else come in.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Sep 2010 16:47:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-incoming-traffic-on-inside-interface/m-p/1578739#M603039</guid>
      <dc:creator>Ian Beck</dc:creator>
      <dc:date>2010-09-21T16:47:04Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM Incoming Traffic on inside Interface</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-incoming-traffic-on-inside-interface/m-p/1578740#M603040</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ian&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may need to post config of the context if you can.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you tried using wireshark on the server to see if it receives the packet and what it does it with it ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you do post the config can you also provide us with the src IP and the dst IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Sep 2010 16:53:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-incoming-traffic-on-inside-interface/m-p/1578740#M603040</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2010-09-21T16:53:41Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM Incoming Traffic on inside Interface</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-incoming-traffic-on-inside-interface/m-p/1578741#M603041</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Context configuration, very simple at the moment as until I can solve this issue I cann not move forward.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Gateway is 172.23.31.2/28 TC3Office nameif&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Sep 2010 17:05:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-incoming-traffic-on-inside-interface/m-p/1578741#M603041</guid>
      <dc:creator>Ian Beck</dc:creator>
      <dc:date>2010-09-21T17:05:29Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM Incoming Traffic on inside Interface</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-incoming-traffic-on-inside-interface/m-p/1578742#M603042</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;src IP and dst IP ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is the src IP the gateway ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edit - are there are shared interfaces int this context ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Sep 2010 17:16:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-incoming-traffic-on-inside-interface/m-p/1578742#M603042</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2010-09-21T17:16:17Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM Incoming Traffic on inside Interface</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-incoming-traffic-on-inside-interface/m-p/1578743#M603043</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have just been able to confirm that packets coming from the Servers reach the destination Server, on the inside, correctly which is then sending a reply back.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Sep 2010 17:17:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-incoming-traffic-on-inside-interface/m-p/1578743#M603043</guid>
      <dc:creator>Ian Beck</dc:creator>
      <dc:date>2010-09-21T17:17:36Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM Incoming Traffic on inside Interface</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-incoming-traffic-on-inside-interface/m-p/1578744#M603044</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A source packet can come from the 172.16.50.0 Network going to either the 172.23.16/17 Networks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;admin-context admin&lt;BR /&gt;context admin&lt;BR /&gt;&amp;nbsp; allocate-interface Vlan300&lt;BR /&gt;&amp;nbsp; config-url disk:/admin.cfg&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;context TC3inside&lt;BR /&gt;&amp;nbsp; allocate-interface Vlan300&lt;BR /&gt;&amp;nbsp; allocate-interface Vlan316&lt;BR /&gt;&amp;nbsp; allocate-interface Vlan317&lt;BR /&gt;&amp;nbsp; allocate-interface Vlan393&lt;BR /&gt;&amp;nbsp; allocate-interface Vlan394&lt;BR /&gt;&amp;nbsp; config-url disk:/TC3inside.cfg&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;context TC3outside&lt;BR /&gt;&amp;nbsp; allocate-interface Vlan301&lt;BR /&gt;&amp;nbsp; allocate-interface Vlan302&lt;BR /&gt;&amp;nbsp; allocate-interface Vlan303&lt;BR /&gt;&amp;nbsp; allocate-interface Vlan392&lt;BR /&gt;&amp;nbsp; config-url disk:/TC3outside.cfg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Sep 2010 17:22:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-incoming-traffic-on-inside-interface/m-p/1578744#M603044</guid>
      <dc:creator>Ian Beck</dc:creator>
      <dc:date>2010-09-21T17:22:01Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM Incoming Traffic on inside Interface</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-incoming-traffic-on-inside-interface/m-p/1578745#M603045</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A real quick test.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make the admin-context TC3inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remove vlan 300 from the admin context.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See if it works&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;conf t&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;admin-context TC3inside&lt;BR /&gt; context admin&lt;BR /&gt;&amp;nbsp; no allocate-interface Vlan300&lt;BR /&gt;&amp;nbsp; &lt;BR /&gt; &lt;/PRE&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Sep 2010 17:26:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-incoming-traffic-on-inside-interface/m-p/1578745#M603045</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-09-21T17:26:51Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM Incoming Traffic on inside Interface</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-incoming-traffic-on-inside-interface/m-p/1578746#M603046</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Breaking my admin &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Sep 2010 17:28:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-incoming-traffic-on-inside-interface/m-p/1578746#M603046</guid>
      <dc:creator>Ian Beck</dc:creator>
      <dc:date>2010-09-21T17:28:38Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM Incoming Traffic on inside Interface</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-incoming-traffic-on-inside-interface/m-p/1578747#M603047</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I haven't worked with 4.x code so Kusankar can perhaps confirm but if you have a shared interface you used to have to use NAT rules otherwise the classifier does not know which context to send the traffic to ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Sep 2010 17:31:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-incoming-traffic-on-inside-interface/m-p/1578747#M603047</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2010-09-21T17:31:53Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM Incoming Traffic on inside Interface</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-incoming-traffic-on-inside-interface/m-p/1578748#M603048</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So that works, which is great thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So if I have to but NAT in place,&amp;nbsp; could I put it on the Admin side on the same VLAN ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or do I need to have a seperate VLAn for Admin ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Sep 2010 17:35:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-incoming-traffic-on-inside-interface/m-p/1578748#M603048</guid>
      <dc:creator>Ian Beck</dc:creator>
      <dc:date>2010-09-21T17:35:59Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM Incoming Traffic on inside Interface</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-incoming-traffic-on-inside-interface/m-p/1578749#M603049</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;YES !! My very first posting asked if you are sharing vlan.&lt;/P&gt;&lt;P&gt;Anyway, yes, with interfaces that you share you need to provide translation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you use another vlan for management and allocate that to the admin context?&lt;/P&gt;&lt;P&gt;or&lt;/P&gt;&lt;P&gt;Do this.&lt;/P&gt;&lt;P&gt;1. allocate another vlan to the admin context.&amp;nbsp; This doesn't even have to exist in the siwtch's vlan database.&lt;/P&gt;&lt;P&gt;2. now configure this as another interface in the admin context.&lt;/P&gt;&lt;P&gt;3. configure nat in the admin context as well between these two interface from high to low.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, classifier can work properly and not get confused as to which context to send the packets that it receives.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You can read about classifier here: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/fwsm/fwsm40/configuration/guide/contxt_f.html#wp1124172"&gt;http://www.cisco.com/en/US/docs/security/fwsm/fwsm40/configuration/guide/contxt_f.html#wp1124172&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rate the posts that were useful to you and that solved the issue. Pls. make sure to mark the issue resolved if you think it is.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Sep 2010 17:44:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-incoming-traffic-on-inside-interface/m-p/1578749#M603049</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-09-21T17:44:34Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM Incoming Traffic on inside Interface</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-incoming-traffic-on-inside-interface/m-p/1578750#M603050</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, just missing reading the comments but thanks for all the help itis appreciated.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Sep 2010 17:48:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-incoming-traffic-on-inside-interface/m-p/1578750#M603050</guid>
      <dc:creator>Ian Beck</dc:creator>
      <dc:date>2010-09-21T17:48:08Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM Incoming Traffic on inside Interface</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-incoming-traffic-on-inside-interface/m-p/1578751#M603051</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have have reconfigured with the recommendations but still am not getting traffic through.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have stayed with a shared VLAN and added relevant Static Nat's and can get to admin but not my servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also creting the vlan on the admin side needed to be in the VLAN DB as it would not come active !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Sep 2010 12:21:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-incoming-traffic-on-inside-interface/m-p/1578751#M603051</guid>
      <dc:creator>Ian Beck</dc:creator>
      <dc:date>2010-09-22T12:21:20Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM Incoming Traffic on inside Interface</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-incoming-traffic-on-inside-interface/m-p/1578752#M603052</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;FWSM(config)# context admin&lt;BR /&gt;FWSM(config-ctx)# allocate-interface vlan97&lt;BR /&gt;FWSM(config-ctx)# sh vlan&lt;BR /&gt;36, 300-301 , 458, 500, 2646&lt;BR /&gt;FWSM(config-ctx)# ch con admin&lt;BR /&gt;FWSM/admin(config)# int vlan97&lt;BR /&gt;FWSMadmin(config-if)# nameif test&lt;BR /&gt;WARNING: VLAN *97* is not configured.&lt;BR /&gt;INFO: Security level for "test" set to 0 by default.&lt;BR /&gt;FWSM/admin(config-if)# seAccess Rules Download Complete: Memory Utilization: 1%&lt;BR /&gt;c 100&lt;BR /&gt;FWSM/admin(config-if)#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you can see I don't even have this vlan when I issue sh vlan on the FWSM, yet I allocated it and configured it under the admin context.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Sep 2010 12:37:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-incoming-traffic-on-inside-interface/m-p/1578752#M603052</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-09-22T12:37:49Z</dc:date>
    </item>
  </channel>
</rss>

