<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FWSM with a Trunked interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fwsm-with-a-trunked-interface/m-p/1378092#M777028</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a Transparent&lt;SPAN style="background-color: #f8fafd;"&gt; FWSM with about 13 contexts.&amp;nbsp; All works fine except when trying to Firewall an interface that's trunked (with phone and PC on different VLANs) by changing the native VLAN.&amp;nbsp; Access remains to the phone, but is lost to the host:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;VLANs 300 and 350 are outside the FWSM context&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;VLANs 400 and 450 are inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Not Firewalled and &lt;/SPAN&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Works:&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;interface FastEthernet1/4&lt;BR /&gt;switchport&lt;BR /&gt;switchport trunk encapsulation dot1q&lt;BR /&gt;switchport trunk native vlan 350&lt;BR /&gt;switchport mode trunk&lt;BR /&gt;no ip address&lt;BR /&gt;power inline auto max 7000&lt;BR /&gt;spanning-tree portfast&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;&lt;EM&gt;Firewalled and Works:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet5/8&lt;BR /&gt;switchport&lt;BR /&gt;switchport access vlan 400&lt;BR /&gt;switchport mode access&lt;BR /&gt;no ip address&lt;BR /&gt;power inline auto max 7000&lt;BR /&gt;spanning-tree portfast&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;&lt;EM&gt;Firewalled and doesn't work:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;interface FastEthernet1/4&lt;BR /&gt;switchport&lt;BR /&gt;switchport trunk encapsulation dot1q&lt;BR /&gt;switchport trunk native vlan 450&lt;BR /&gt;switchport mode trunk&lt;BR /&gt;no ip address&lt;BR /&gt;power inline auto max 7000&lt;BR /&gt;spanning-tree portfast&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Is it possible to firewall a Trunked Interface?&amp;nbsp; I haven't found any information indicating one way or another.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 16:48:00 GMT</pubDate>
    <dc:creator>gdittman12</dc:creator>
    <dc:date>2019-03-11T16:48:00Z</dc:date>
    <item>
      <title>FWSM with a Trunked interface</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-with-a-trunked-interface/m-p/1378092#M777028</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a Transparent&lt;SPAN style="background-color: #f8fafd;"&gt; FWSM with about 13 contexts.&amp;nbsp; All works fine except when trying to Firewall an interface that's trunked (with phone and PC on different VLANs) by changing the native VLAN.&amp;nbsp; Access remains to the phone, but is lost to the host:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;VLANs 300 and 350 are outside the FWSM context&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;VLANs 400 and 450 are inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Not Firewalled and &lt;/SPAN&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Works:&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;interface FastEthernet1/4&lt;BR /&gt;switchport&lt;BR /&gt;switchport trunk encapsulation dot1q&lt;BR /&gt;switchport trunk native vlan 350&lt;BR /&gt;switchport mode trunk&lt;BR /&gt;no ip address&lt;BR /&gt;power inline auto max 7000&lt;BR /&gt;spanning-tree portfast&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;&lt;EM&gt;Firewalled and Works:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet5/8&lt;BR /&gt;switchport&lt;BR /&gt;switchport access vlan 400&lt;BR /&gt;switchport mode access&lt;BR /&gt;no ip address&lt;BR /&gt;power inline auto max 7000&lt;BR /&gt;spanning-tree portfast&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;&lt;EM&gt;Firewalled and doesn't work:&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;interface FastEthernet1/4&lt;BR /&gt;switchport&lt;BR /&gt;switchport trunk encapsulation dot1q&lt;BR /&gt;switchport trunk native vlan 450&lt;BR /&gt;switchport mode trunk&lt;BR /&gt;no ip address&lt;BR /&gt;power inline auto max 7000&lt;BR /&gt;spanning-tree portfast&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Is it possible to firewall a Trunked Interface?&amp;nbsp; I haven't found any information indicating one way or another.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:48:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-with-a-trunked-interface/m-p/1378092#M777028</guid>
      <dc:creator>gdittman12</dc:creator>
      <dc:date>2019-03-11T16:48:00Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM with a Trunked interface</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-with-a-trunked-interface/m-p/1378093#M777055</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The FWSM has no concept of trunks.&lt;/P&gt;&lt;P&gt;Each of its interfaces is a vlan.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Whatever the FWSM sees in a vlan it is trunking it "firewalls" it. Meaning a packet, depending what vlan tag it has it is picked by the correct interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, the FWSM cannot do trunks as you know them.&lt;/P&gt;&lt;P&gt;If the pc and phone are in different vlans then both would need to be pushed to FWSM and "firewalled".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 12 Dec 2009 00:53:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-with-a-trunked-interface/m-p/1378093#M777055</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2009-12-12T00:53:48Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM with a Trunked interface</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-with-a-trunked-interface/m-p/1378094#M777078</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply, but I'm still not clear if it's possible to have a use a context with a device connected to a interface that is configured as Trunked.&amp;nbsp; I realize that the FWSM has no concept of Trunks and is connected by a Trunk itself, but the traffic going to the two devices is "switched" going into the Interface.&amp;nbsp; Why can't the action be that the Tagged traffic go to the FWSM and then back to the interface (and then Trunked), as it would if the interface was configured as switched?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You also state: "If the pc and phone are in different vlans then both would need to be pushed to FWSM and "firewalled".", Are you just stating to move to different ports?&amp;nbsp; I'm unclear what your meaning is here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Dec 2009 19:39:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-with-a-trunked-interface/m-p/1378094#M777078</guid>
      <dc:creator>gdittman12</dc:creator>
      <dc:date>2009-12-14T19:39:45Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM with a Trunked interface</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-with-a-trunked-interface/m-p/1378095#M777088</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Let's say you have a pc that connects to vlan x and a phone that is vlan y.&lt;/P&gt;&lt;P&gt;There is a trunk that passes vlans x,y.&lt;/P&gt;&lt;P&gt;The phone packets have vland id x and the phone vlan id y.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;They come into the switch. The switch routes or switches them depending on the setup. If they are destined to the L3 vlanx,y ip address it routes, if they are destined to a vlanx or y mac that is not the switches then it just switches the packet at L2. In any case the packet will need to be picked up by the FWSM if you want it firewalled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In other words if the FWSM has vlan x and y as interfaces (L3 mode) and if need be the switch has next hop for the traffic sourced from the phone or pc (switch routing scenario) it should forward the packets to the FWSM and that should act accordingly. If was are a L3 and the switch just switches the packets it should just pass them at layer 2 to the FWSM and that should pass them. Trunk or non trunk, the switch reads the tags and does its job for the vlan the packets are coming in on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Dec 2009 20:40:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-with-a-trunked-interface/m-p/1378095#M777088</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2009-12-14T20:40:18Z</dc:date>
    </item>
  </channel>
</rss>

