<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FW in VSS Environment in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fw-in-vss-environment/m-p/1312516#M859203</link>
    <description>&lt;P&gt;Working in a VSS environment, one firewall in each catalyst, configured with two context and Active / Passive scenario. One VLAN exist between two context, but no communication between context over the VLAN. ARP is showing same mac-address on two different VLAN and on two different context.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Context APP:&lt;/P&gt;&lt;P&gt;        Inside 172.20.0.10 001b.380c.7e4c &lt;/P&gt;&lt;P&gt;        Inside 172.20.70.249 001b.380c.7e4c &lt;/P&gt;&lt;P&gt;        Inside 172.20.0.5 001b.380d.0357 &lt;/P&gt;&lt;P&gt;        DMZ.NMS 172.16.12.7 0023.334d.e3bc &lt;/P&gt;&lt;P&gt;        DMZ.NMS 172.16.12.6 0023.334d.e37c &lt;/P&gt;&lt;P&gt;        Outside.INT 172.16.10.3 0024.971f.4900 &lt;/P&gt;&lt;P&gt;        Outside.EDN 172.16.10.37 0025.45f4.7000 &lt;/P&gt;&lt;P&gt;        Outside.EDN 172.16.10.35 0024.971f.4900 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Context INT&lt;/P&gt;&lt;P&gt;       Outside.INT 202.14.71.165 0013.c34d.1ad0 &lt;/P&gt;&lt;P&gt;        Inside.INT 172.16.10.2 0024.971f.4d00 &lt;/P&gt;&lt;P&gt;        Inside.INT 172.16.10.1 0024.971f.4900 &lt;/P&gt;&lt;P&gt;        Inside.EDN 172.16.10.33 0024.971f.4900 &lt;/P&gt;&lt;P&gt;        Inside.EDN 172.16.10.37 0025.45f4.7000 &lt;/P&gt;&lt;P&gt;        DMZ2 202.125.132.154 0014.5e18.a042 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Same mac-address entry on security interface Outside.EDN, Outside.INT, Inside.INT and Inside.EDN.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 15:46:11 GMT</pubDate>
    <dc:creator>Ahmed Shahzad</dc:creator>
    <dc:date>2019-03-11T15:46:11Z</dc:date>
    <item>
      <title>FW in VSS Environment</title>
      <link>https://community.cisco.com/t5/network-security/fw-in-vss-environment/m-p/1312516#M859203</link>
      <description>&lt;P&gt;Working in a VSS environment, one firewall in each catalyst, configured with two context and Active / Passive scenario. One VLAN exist between two context, but no communication between context over the VLAN. ARP is showing same mac-address on two different VLAN and on two different context.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Context APP:&lt;/P&gt;&lt;P&gt;        Inside 172.20.0.10 001b.380c.7e4c &lt;/P&gt;&lt;P&gt;        Inside 172.20.70.249 001b.380c.7e4c &lt;/P&gt;&lt;P&gt;        Inside 172.20.0.5 001b.380d.0357 &lt;/P&gt;&lt;P&gt;        DMZ.NMS 172.16.12.7 0023.334d.e3bc &lt;/P&gt;&lt;P&gt;        DMZ.NMS 172.16.12.6 0023.334d.e37c &lt;/P&gt;&lt;P&gt;        Outside.INT 172.16.10.3 0024.971f.4900 &lt;/P&gt;&lt;P&gt;        Outside.EDN 172.16.10.37 0025.45f4.7000 &lt;/P&gt;&lt;P&gt;        Outside.EDN 172.16.10.35 0024.971f.4900 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Context INT&lt;/P&gt;&lt;P&gt;       Outside.INT 202.14.71.165 0013.c34d.1ad0 &lt;/P&gt;&lt;P&gt;        Inside.INT 172.16.10.2 0024.971f.4d00 &lt;/P&gt;&lt;P&gt;        Inside.INT 172.16.10.1 0024.971f.4900 &lt;/P&gt;&lt;P&gt;        Inside.EDN 172.16.10.33 0024.971f.4900 &lt;/P&gt;&lt;P&gt;        Inside.EDN 172.16.10.37 0025.45f4.7000 &lt;/P&gt;&lt;P&gt;        DMZ2 202.125.132.154 0014.5e18.a042 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Same mac-address entry on security interface Outside.EDN, Outside.INT, Inside.INT and Inside.EDN.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:46:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fw-in-vss-environment/m-p/1312516#M859203</guid>
      <dc:creator>Ahmed Shahzad</dc:creator>
      <dc:date>2019-03-11T15:46:11Z</dc:date>
    </item>
    <item>
      <title>Re: FW in VSS Environment</title>
      <link>https://community.cisco.com/t5/network-security/fw-in-vss-environment/m-p/1312517#M859205</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What is the question? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWSM only has one MAC address.  So, you will see the same MAC address on all the vlans. Since the interface is shared between the two contexts you will see the same MAC there as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you share the outside interface, then you have to make sure to translate the inside networks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you share the inside interface, you need to translated the outside network (this gets ugly if the outside interface faces the internet).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pls. read below:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/fwsm/fwsm32/configuration/guide/contxt_f.html#wp1124236" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/fwsm/fwsm32/configuration/guide/contxt_f.html#wp1124236&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jun 2009 19:12:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fw-in-vss-environment/m-p/1312517#M859205</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2009-06-22T19:12:38Z</dc:date>
    </item>
  </channel>
</rss>

