<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FWSM design question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fwsm-design-question/m-p/1390393#M748147</link>
    <description>&lt;P&gt;Are there any pros and cons to the way an FWSM can be implemented in a 6509?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For instance, our WLAN deployment sits on four WiSMs in a 6509.&amp;nbsp; We have a FWSM in the 6509 with an inside and outside VLAN, and a static route pointing to the inside of the FWSM from the 6509.&amp;nbsp; All traffic goes to the interface of the FWSM, gets PAT'd out through one IP address and that's it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have been reading that I can move the gateway addresses to the FWSM from the 6509 and PAT each range out through the FWSM, but this time I would PAT each VLAN out through its own IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm wondering if there are any advantages or disadvantages.&amp;nbsp; The latter description would be a lot more work, but provide more granularity.&amp;nbsp; I can also simply change our current deployment to PAT each VLAN out through its own mapped IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Either way will result in traffic flowing, but is there a "more right" way to do this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Tim&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 17:20:25 GMT</pubDate>
    <dc:creator>tdennehy</dc:creator>
    <dc:date>2019-03-11T17:20:25Z</dc:date>
    <item>
      <title>FWSM design question</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-design-question/m-p/1390393#M748147</link>
      <description>&lt;P&gt;Are there any pros and cons to the way an FWSM can be implemented in a 6509?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For instance, our WLAN deployment sits on four WiSMs in a 6509.&amp;nbsp; We have a FWSM in the 6509 with an inside and outside VLAN, and a static route pointing to the inside of the FWSM from the 6509.&amp;nbsp; All traffic goes to the interface of the FWSM, gets PAT'd out through one IP address and that's it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have been reading that I can move the gateway addresses to the FWSM from the 6509 and PAT each range out through the FWSM, but this time I would PAT each VLAN out through its own IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm wondering if there are any advantages or disadvantages.&amp;nbsp; The latter description would be a lot more work, but provide more granularity.&amp;nbsp; I can also simply change our current deployment to PAT each VLAN out through its own mapped IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Either way will result in traffic flowing, but is there a "more right" way to do this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Tim&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:20:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-design-question/m-p/1390393#M748147</guid>
      <dc:creator>tdennehy</dc:creator>
      <dc:date>2019-03-11T17:20:25Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM design question</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-design-question/m-p/1390394#M748155</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is really not much difference or advantages.&lt;/P&gt;&lt;P&gt;One I could think of is you have 65K ports for translation if you PAT everything from the inside which depending on traffic might at some point make you run out of PAT ports.&lt;/P&gt;&lt;P&gt;If you use separate PAT ip addresses for different internal ip ranges then you are less likely to run out of ports to PAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't see any other disadvantage since the FWSM will perform fine with both.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Mar 2010 17:48:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-design-question/m-p/1390394#M748155</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-03-11T17:48:48Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM design question</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-design-question/m-p/1390395#M748163</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;tdennehy wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are there any pros and cons to the way an FWSM can be implemented in a 6509?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For instance, our WLAN deployment sits on four WiSMs in a 6509.&amp;nbsp; We have a FWSM in the 6509 with an inside and outside VLAN, and a static route pointing to the inside of the FWSM from the 6509.&amp;nbsp; All traffic goes to the interface of the FWSM, gets PAT'd out through one IP address and that's it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have been reading that I can move the gateway addresses to the FWSM from the 6509 and PAT each range out through the FWSM, but this time I would PAT each VLAN out through its own IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm wondering if there are any advantages or disadvantages.&amp;nbsp; The latter description would be a lot more work, but provide more granularity.&amp;nbsp; I can also simply change our current deployment to PAT each VLAN out through its own mapped IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Either way will result in traffic flowing, but is there a "more right" way to do this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Tim&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tim&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So you have -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vlans -&amp;gt; (inside) FWSM (outside) -&amp;gt; MSFC ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edit - sorry meant to be -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vlans -&amp;gt; MSFC -&amp;gt; (inside) FWSM (outside)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If so the deployment o the FWSM is nothing really to do with PAT. You wouldn't need to move the gateways to the FWSM to be able to PAT each vlan to a different PAT address ie.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 1 172.16.5.0 255.255.255.0&lt;/P&gt;&lt;P&gt;nat (inside) 2 172.16.6.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 PAT1&lt;/P&gt;&lt;P&gt;global (outside) 2 PAT2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the above would translate the 2 separate vlans to different PAT addresses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Whether to have the gateways for the vlans on the FWSM or the MSFC is to do with whether you want/need to firewall between those vlans. If you don't then you don't need to have their gateways on the FWSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If i have misunderstood your topology or question then please clarify.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Mar 2010 19:02:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-design-question/m-p/1390395#M748163</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2010-03-11T19:02:12Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM design question</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-design-question/m-p/1390396#M748169</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When you say the 6509 is pointing to the FWSM's inside interface for the default gateway the topology is&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MSFC -&amp;gt; (inside) FWSM (outside) -&amp;gt; Internet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon is correct.&amp;nbsp; With just those few lines that he gave you, you can PAT each vlan to a different global address. This will be good from the admin side of things as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the other vlans are different interfaces on the FWSM then you can use change the same example around.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 1 172.16.5.0 255.255.255.0&lt;/P&gt;&lt;P&gt;nat (inside-2) 2 172.16.6.0 255.255.255.0&lt;/P&gt;&lt;P&gt;nat (inside-3) 2 172.16.7.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 PAT1&lt;/P&gt;&lt;P&gt;global (outside) 2 PAT2&lt;/P&gt;&lt;P&gt;global (outisde) 3 PAT3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Mar 2010 19:20:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-design-question/m-p/1390396#M748169</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-03-11T19:20:20Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM design question</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-design-question/m-p/1390397#M748177</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is how we do it now, Kusankar.&amp;nbsp; I think I'll keep doing it this way, since I am not hearing any compelling reasons from anyone to change to having the gateway addresses on the FWSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can do it either way, and since there is a choice, I was wondering which is the better way.&amp;nbsp; Turns out I don't think there is a better way - they both seem to be "the right way".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-=Tim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Mar 2010 20:10:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-design-question/m-p/1390397#M748177</guid>
      <dc:creator>tdennehy</dc:creator>
      <dc:date>2010-03-11T20:10:00Z</dc:date>
    </item>
  </channel>
</rss>

