<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FWSM in transparent mode in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fwsm-in-transparent-mode/m-p/1462343#M642203</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you...that was my misunderstanding.&amp;nbsp; Both VLANs are using the same subnet linked back together by the bridge-group --- the pieces all fit now! &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 10 Jun 2010 18:36:59 GMT</pubDate>
    <dc:creator>Chris Brun</dc:creator>
    <dc:date>2010-06-10T18:36:59Z</dc:date>
    <item>
      <title>FWSM in transparent mode</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-in-transparent-mode/m-p/1462339#M642188</link>
      <description>&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: Times New Roman; color: #000000; font-size: 12pt;"&gt;Attempting to set up the FWSM in transparent mode (single context).&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;Here is my scenario:&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;I have a 6509 with 3 VLANs…40 (DMZ), 41 (Staff), and 42 (Inside).&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;I would like to use the FWSM to control access transparently between the 3 VLANs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: Times New Roman; color: #000000; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: Times New Roman; color: #000000; font-size: 12pt;"&gt;Here is what I have set up:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;STRONG style="mso-bidi-font-weight: normal; : ; color: #000000; font-size: 12pt; font-family: Times New Roman; "&gt;6509&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style=": ; Courier New&amp;amp;quot: ; color: #000000; font-size: 9pt; font-family: &amp;amp;quot; "&gt;firewall multiple-vlan-interfaces&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style=": ; Courier New&amp;amp;quot: ; color: #000000; font-size: 9pt; font-family: &amp;amp;quot; "&gt;firewall module 7 vlan-group 40&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style=": ; Courier New&amp;amp;quot: ; color: #000000; font-size: 9pt; font-family: &amp;amp;quot; "&gt;firewall vlan-group 40&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;40-42&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style=": ; Courier New&amp;amp;quot: ; color: #000000; font-size: 9pt; font-family: &amp;amp;quot; "&gt;interface Vlan40&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style=": ; Courier New&amp;amp;quot: ; color: #000000; font-size: 9pt; font-family: &amp;amp;quot; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;ip address 10.40.0.1 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style=": ; Courier New&amp;amp;quot: ; color: #000000; font-size: 9pt; font-family: &amp;amp;quot; "&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style=": ; Courier New&amp;amp;quot: ; color: #000000; font-size: 9pt; font-family: &amp;amp;quot; "&gt;interface Vlan41&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style=": ; Courier New&amp;amp;quot: ; color: #000000; font-size: 9pt; font-family: &amp;amp;quot; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;ip address 10.41.0.1 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style=": ; Courier New&amp;amp;quot: ; color: #000000; font-size: 9pt; font-family: &amp;amp;quot; "&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style=": ; Courier New&amp;amp;quot: ; color: #000000; font-size: 9pt; font-family: &amp;amp;quot; "&gt;interface Vlan42&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style=": ; Courier New&amp;amp;quot: ; color: #000000; font-size: 9pt; font-family: &amp;amp;quot; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;ip address 10.42.0.1 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style=": ; Courier New&amp;amp;quot: ; color: #000000; font-size: 9pt; font-family: &amp;amp;quot; "&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;STRONG style="mso-bidi-font-weight: normal; : ; color: #000000; font-size: 12pt; font-family: Times New Roman; "&gt;FWSM&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style=": ; Courier New&amp;amp;quot: ; color: #000000; font-size: 9pt; font-family: &amp;amp;quot; "&gt;FWSM Version 3.1(10)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style=": ; Courier New&amp;amp;quot: ; color: #000000; font-size: 9pt; font-family: &amp;amp;quot; "&gt;firewall transparent&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style=": ; Courier New&amp;amp;quot: ; color: #000000; font-size: 9pt; font-family: &amp;amp;quot; "&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style=": ; Courier New&amp;amp;quot: ; color: #000000; font-size: 9pt; font-family: &amp;amp;quot; "&gt;interface Vlan40&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style=": ; Courier New&amp;amp;quot: ; color: #000000; font-size: 9pt; font-family: &amp;amp;quot; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;nameif DMZ&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style=": ; Courier New&amp;amp;quot: ; color: #000000; font-size: 9pt; font-family: &amp;amp;quot; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;bridge-group 1&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style=": ; Courier New&amp;amp;quot: ; color: #000000; font-size: 9pt; font-family: &amp;amp;quot; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;security-level 0&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style=": ; Courier New&amp;amp;quot: ; color: #000000; font-size: 9pt; font-family: &amp;amp;quot; "&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style=": ; Courier New&amp;amp;quot: ; color: #000000; font-size: 9pt; font-family: &amp;amp;quot; "&gt;interface Vlan41&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style=": ; Courier New&amp;amp;quot: ; color: #000000; font-size: 9pt; font-family: &amp;amp;quot; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;nameif Staff&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style=": ; Courier New&amp;amp;quot: ; color: #000000; font-size: 9pt; font-family: &amp;amp;quot; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;bridge-group 2&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style=": ; Courier New&amp;amp;quot: ; color: #000000; font-size: 9pt; font-family: &amp;amp;quot; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;security-level 50&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style=": ; Courier New&amp;amp;quot: ; color: #000000; font-size: 9pt; font-family: &amp;amp;quot; "&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style=": ; Courier New&amp;amp;quot: ; color: #000000; font-size: 9pt; font-family: &amp;amp;quot; "&gt;interface Vlan42&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style=": ; Courier New&amp;amp;quot: ; color: #000000; font-size: 9pt; font-family: &amp;amp;quot; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;nameif Inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style=": ; Courier New&amp;amp;quot: ; color: #000000; font-size: 9pt; font-family: &amp;amp;quot; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;bridge-group 3&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style=": ; Courier New&amp;amp;quot: ; color: #000000; font-size: 9pt; font-family: &amp;amp;quot; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;security-level 100&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style=": ; Courier New&amp;amp;quot: ; color: #000000; font-size: 9pt; font-family: &amp;amp;quot; "&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style=": ; Courier New&amp;amp;quot: ; color: #000000; font-size: 9pt; font-family: &amp;amp;quot; "&gt;access-list DENY-ALL extended deny ip any any log&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style=": ; Courier New&amp;amp;quot: ; color: #000000; font-size: 9pt; font-family: &amp;amp;quot; "&gt;access-list DENY-ALL extended deny icmp any any log&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style=": ; Courier New&amp;amp;quot: ; color: #000000; font-size: 9pt; font-family: &amp;amp;quot; "&gt;access-group DENY-ALL in interface DMZ&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: Times New Roman; color: #000000; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: Times New Roman; color: #000000; font-size: 12pt;"&gt;I understood that without any ACLs, the default action would be deny, however I was able to communicate freely between all the VLANs.&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;I added the ACL to explicitly deny anything from the DMZ, but still able to communicate.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: Times New Roman; color: #000000; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: Times New Roman; color: #000000; font-size: 12pt;"&gt;Would appreciate any assistance in how I can get the FWSM in transparent mode to control traffic between 3 VLANs.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:56:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-in-transparent-mode/m-p/1462339#M642188</guid>
      <dc:creator>Chris Brun</dc:creator>
      <dc:date>2019-03-11T17:56:07Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM in transparent mode</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-in-transparent-mode/m-p/1462340#M642192</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;Pls. follow the sample here: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/fwsm/fwsm31/configuration/guide/exampl_f.html#wp1029042"&gt;http://www.cisco.com/en/US/docs/security/fwsm/fwsm31/configuration/guide/exampl_f.html#wp1029042&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need two vlans in a bridge group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Transparent firewall overview: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/fwsm/fwsm31/configuration/guide/fwmode_f.html#wp1220104"&gt;http://www.cisco.com/en/US/docs/security/fwsm/fwsm31/configuration/guide/fwmode_f.html#wp1220104&lt;/A&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jun 2010 14:12:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-in-transparent-mode/m-p/1462340#M642192</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-06-08T14:12:00Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM in transparent mode</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-in-transparent-mode/m-p/1462341#M642199</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I "think" I followed the instructions ... placing two VLANs in a single bridge_group (although that goes against everything I believe about routing!) ... but still can not seem to control access between VLAN 40 &amp;amp; 41.&amp;nbsp; I still have full access between devices on both subnets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;interface Vlan40&lt;BR /&gt; nameif DMZ&lt;BR /&gt; bridge-group 1&lt;BR /&gt; security-level 0&lt;BR /&gt;!&lt;BR /&gt;interface Vlan41&lt;BR /&gt; nameif Schools&lt;BR /&gt; bridge-group 1&lt;BR /&gt; security-level 50&lt;BR /&gt;!&lt;BR /&gt;access-list DENY-ALL extended deny ip any any log&lt;BR /&gt;access-list DENY-ALL extended deny icmp any any log&lt;BR /&gt;access-group DENY-ALL in interface DMZ&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Appriciate any advice.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Jun 2010 14:16:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-in-transparent-mode/m-p/1462341#M642199</guid>
      <dc:creator>Chris Brun</dc:creator>
      <dc:date>2010-06-10T14:16:28Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM in transparent mode</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-in-transparent-mode/m-p/1462342#M642200</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Vlan 40 and 41 should be in the same subnet.&lt;/P&gt;&lt;P&gt;But hosts on switchports vlan access 40 and 41 will go through the FWSM that will be bridging these vlans.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So make sure you have 2 ports with hosts in each vlan and that their ip addresses are in the same subnet.&lt;/P&gt;&lt;P&gt;try pinging between them and then the FWSM should be bridging and you will see traffic through it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Jun 2010 18:20:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-in-transparent-mode/m-p/1462342#M642200</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-06-10T18:20:07Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM in transparent mode</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-in-transparent-mode/m-p/1462343#M642203</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you...that was my misunderstanding.&amp;nbsp; Both VLANs are using the same subnet linked back together by the bridge-group --- the pieces all fit now! &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Jun 2010 18:36:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-in-transparent-mode/m-p/1462343#M642203</guid>
      <dc:creator>Chris Brun</dc:creator>
      <dc:date>2010-06-10T18:36:59Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM in transparent mode</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-in-transparent-mode/m-p/1462344#M642204</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yup, glad it helped.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Jun 2010 18:45:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-in-transparent-mode/m-p/1462344#M642204</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-06-10T18:45:24Z</dc:date>
    </item>
  </channel>
</rss>

