<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firewall multiple-vlan-interfaces ( 6509 &amp; FWSM) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firewall-multiple-vlan-interfaces-6509-fwsm/m-p/1416398#M731570</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have a setup in which i had msfc svi configured on 6509 which is also configured on fwsm with the same subnet ip address to setup communication between msfc and firewall. its working fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now we had requirement of configuring second interface with new subnet on 6509 which should be also present on fwsm with the same new subnet on fwsm.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is newly created SVI's remain administratively down on 6509. do i have to use "firewall multiple-vlan-interfaces" command on 6509..to create multiple svi interfaces between msfc and fwsm ? If yes, when i introduce this command, does it hamper the existing traffic going from msfc to fwsm...?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hitesh Vinzoda&lt;/P&gt;</description>
    <pubDate>Wed, 13 Mar 2019 00:59:51 GMT</pubDate>
    <dc:creator>Hitesh Vinzoda</dc:creator>
    <dc:date>2019-03-13T00:59:51Z</dc:date>
    <item>
      <title>Firewall multiple-vlan-interfaces ( 6509 &amp; FWSM)</title>
      <link>https://community.cisco.com/t5/network-security/firewall-multiple-vlan-interfaces-6509-fwsm/m-p/1416398#M731570</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have a setup in which i had msfc svi configured on 6509 which is also configured on fwsm with the same subnet ip address to setup communication between msfc and firewall. its working fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now we had requirement of configuring second interface with new subnet on 6509 which should be also present on fwsm with the same new subnet on fwsm.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is newly created SVI's remain administratively down on 6509. do i have to use "firewall multiple-vlan-interfaces" command on 6509..to create multiple svi interfaces between msfc and fwsm ? If yes, when i introduce this command, does it hamper the existing traffic going from msfc to fwsm...?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hitesh Vinzoda&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2019 00:59:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-multiple-vlan-interfaces-6509-fwsm/m-p/1416398#M731570</guid>
      <dc:creator>Hitesh Vinzoda</dc:creator>
      <dc:date>2019-03-13T00:59:51Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall multiple-vlan-interfaces ( 6509 &amp; FWSM)</title>
      <link>https://community.cisco.com/t5/network-security/firewall-multiple-vlan-interfaces-6509-fwsm/m-p/1416399#M731580</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;hitesh.vinzoda wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have a setup in which i had msfc svi configured on 6509 which is also configured on fwsm with the same subnet ip address to setup communication between msfc and firewall. its working fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now we had requirement of configuring second interface with new subnet on 6509 which should be also present on fwsm with the same new subnet on fwsm.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is newly created SVI's remain administratively down on 6509. do i have to use "firewall multiple-vlan-interfaces" command on 6509..to create multiple svi interfaces between msfc and fwsm ? If yes, when i introduce this command, does it hamper the existing traffic going from msfc to fwsm...?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hitesh Vinzoda&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hitesh&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to have multiple L3 SVIs up/up on the 6509 and have the FWSM use these vlans as well then yes you will need to enable "firewall multiple-vlan-interfaces".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to be careful when using this command. If you have multiple L3 SVIs for vlans attached to the FWSM you need to make sure that you have not bypassed the firewall eg.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2 vlans - vlan 10 &amp;amp; 11&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;both vlans should be firewalled by the FWSM. If you create a L3 SVI for both vlans on the MSFC then traffic will simply be routed by the MSFC between the 2 vlans ie. it will not go via the FWSM. So you need to make sure that by enabling "firewall multiple-vlan-interfaces" and having a 2nd SVI on the MSFC you have actually bypassed the FWSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It should not hamper the existing traffic other than the above scenario where you may find you have bypassed the FWSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Jan 2010 09:56:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-multiple-vlan-interfaces-6509-fwsm/m-p/1416399#M731580</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2010-01-22T09:56:49Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall multiple-vlan-interfaces ( 6509 &amp; FWSM)</title>
      <link>https://community.cisco.com/t5/network-security/firewall-multiple-vlan-interfaces-6509-fwsm/m-p/1416400#M731591</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my case, my 2 vlans, vlan 10 belongs to GRT and vlan 11 belongs to vrf. So if they want to get route they will not use msfc rather it will go to firewall and based on policy they will have access to each other.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;plese advice... on this hypothesis&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hitesh Vinzoda&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 23 Jan 2010 09:37:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-multiple-vlan-interfaces-6509-fwsm/m-p/1416400#M731591</guid>
      <dc:creator>Hitesh Vinzoda</dc:creator>
      <dc:date>2010-01-23T09:37:14Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall multiple-vlan-interfaces ( 6509 &amp; FWSM)</title>
      <link>https://community.cisco.com/t5/network-security/firewall-multiple-vlan-interfaces-6509-fwsm/m-p/1416401#M731603</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;hitesh.vinzoda wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my case, my 2 vlans, vlan 10 belongs to GRT and vlan 11 belongs to vrf. So if they want to get route they will not use msfc rather it will go to firewall and based on policy they will have access to each other.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;plese advice... on this hypothesis&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hitesh Vinzoda&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hitesh&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have never used this type of setup but what you say makes perfect sense ie. traffic will have to be routed via the FWSM. So you should enable "firewall multiple-vlan-interfaces".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 23 Jan 2010 12:56:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-multiple-vlan-interfaces-6509-fwsm/m-p/1416401#M731603</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2010-01-23T12:56:19Z</dc:date>
    </item>
  </channel>
</rss>

