<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FWSM and multiple-vlan-interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fwsm-and-multiple-vlan-interface/m-p/1237473#M876229</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Annie&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could either&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) use a VRF for the servers as you say &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OR &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) create an interface for each server vlan on the FWSM so in effect each server vlan gets it's own DMZ. If you don't want to firewall the traffic from one server vlan to another then you can use &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"permit ip any any" between the server vlans. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Each of these server vlans must not have a L3 SVI on the MSFC ie. their default-gateway per vlan is an interface on the FWSM. So the only way to get to them is via the FWSM. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Out of the 2 options i have only deployed option 2 so i can't say what gotcha's there will be with the VRF solution.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also worth bearing mind. If there is a lot of traffic flowing between these server vlans then the VRF approach may be a better approach because this traffic can be routed via the MSFC rather than have to go through the FWSM and only traffic from non-server vlans would have to go through the FWSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does this make sense ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 18 Feb 2009 17:53:20 GMT</pubDate>
    <dc:creator>Jon Marshall</dc:creator>
    <dc:date>2009-02-18T17:53:20Z</dc:date>
    <item>
      <title>FWSM and multiple-vlan-interface</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-and-multiple-vlan-interface/m-p/1237469#M876225</link>
      <description>&lt;P&gt;We are using a CAT 6500 with a FWSM.  I need to know if, by enabling multiple-vlan-interface on the switch, will that force vlans from one firewall-group to pass thru the FWSM to reach vlans on another firewall-group (all vlans defined in the same mfsc)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or will traffic from all of the non-firewall VLANs in the switch be routed through the MSFC without being stopped by the firewall, even if these vlans are defined in different firewall-groups?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your input.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 14:52:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-and-multiple-vlan-interface/m-p/1237469#M876225</guid>
      <dc:creator>anniet</dc:creator>
      <dc:date>2019-03-11T14:52:02Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM and multiple-vlan-interface</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-and-multiple-vlan-interface/m-p/1237470#M876226</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Annie&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It totally depends on the topology of your network. Have a look at this thread i did a while back which explains exactly what the command does - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A jive-link-custom=""&gt;http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Security&amp;amp;topic=Firewalling&amp;amp;topicID=.ee6e1fa&amp;amp;CommCmd=MB%3Fcmd%3Dpass_through%26location%3Doutline%40%5E1%40%40.2cc0a239/0#selected_message&lt;/A&gt;')"&amp;gt;&lt;A class="jive-link-custom" href="http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Security&amp;amp;topic=Firewalling&amp;amp;topicID=.ee6e1fa&amp;amp;CommCmd=MB%3Fcmd%3Dpass_through%26location%3Doutline%40%5E1%40%40.2cc0a239/0#selected_message" target="_blank"&gt;http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Security&amp;amp;topic=Firewalling&amp;amp;topicID=.ee6e1fa&amp;amp;CommCmd=MB%3Fcmd%3Dpass_through%26location%3Doutline%40%5E1%40%40.2cc0a239/0#selected_message&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this doesn't answer your question then please come back with more details.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Feb 2009 22:44:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-and-multiple-vlan-interface/m-p/1237470#M876226</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2009-02-17T22:44:00Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM and multiple-vlan-interface</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-and-multiple-vlan-interface/m-p/1237471#M876227</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, previous link seems to have got messed up - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Security&amp;amp;topic=Firewalling&amp;amp;topicID=.ee6e1fa&amp;amp;CommCmd=MB%3Fcmd%3Dpass_through%26location%3Doutline%40%5E1%40%40.2cc0a239/0#selected_message" target="_blank"&gt;http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Security&amp;amp;topic=Firewalling&amp;amp;topicID=.ee6e1fa&amp;amp;CommCmd=MB%3Fcmd%3Dpass_through%26location%3Doutline%40%5E1%40%40.2cc0a239/0#selected_message&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Feb 2009 22:52:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-and-multiple-vlan-interface/m-p/1237471#M876227</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2009-02-17T22:52:18Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM and multiple-vlan-interface</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-and-multiple-vlan-interface/m-p/1237472#M876228</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess that is why I read "some PBR may be required".  I have about 5 vlans in the server farm and I want all traffic going to the server farm to be firewalled.  We were thinking about grouping the server farm's vlans into a VRF to make sure all traffic goes thru the FWSM.  Does that sound good or do you have any other suggestions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Annie&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Feb 2009 16:20:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-and-multiple-vlan-interface/m-p/1237472#M876228</guid>
      <dc:creator>anniet</dc:creator>
      <dc:date>2009-02-18T16:20:32Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM and multiple-vlan-interface</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-and-multiple-vlan-interface/m-p/1237473#M876229</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Annie&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could either&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) use a VRF for the servers as you say &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OR &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) create an interface for each server vlan on the FWSM so in effect each server vlan gets it's own DMZ. If you don't want to firewall the traffic from one server vlan to another then you can use &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"permit ip any any" between the server vlans. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Each of these server vlans must not have a L3 SVI on the MSFC ie. their default-gateway per vlan is an interface on the FWSM. So the only way to get to them is via the FWSM. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Out of the 2 options i have only deployed option 2 so i can't say what gotcha's there will be with the VRF solution.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also worth bearing mind. If there is a lot of traffic flowing between these server vlans then the VRF approach may be a better approach because this traffic can be routed via the MSFC rather than have to go through the FWSM and only traffic from non-server vlans would have to go through the FWSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does this make sense ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Feb 2009 17:53:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-and-multiple-vlan-interface/m-p/1237473#M876229</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2009-02-18T17:53:20Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM and multiple-vlan-interface</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-and-multiple-vlan-interface/m-p/1237474#M876230</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your input.  It helped us confirm our thoughts.  I actually lied earlier about the 5 vlans in the server farm, we have 24.  Ridiculous I know, but that's the network setup I inherited.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No way we are going to define all those interfaces in the FWSM, and like you mentionned, we don't really want to firewall between those vlans,  so VRF is how we are going to group them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Annie&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Feb 2009 22:20:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-and-multiple-vlan-interface/m-p/1237474#M876230</guid>
      <dc:creator>anniet</dc:creator>
      <dc:date>2009-02-18T22:20:18Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM and multiple-vlan-interface</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-and-multiple-vlan-interface/m-p/1237475#M876233</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Annie&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"I actually lied earlier about the 5 vlans in the server farm, we have 24."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ah well then i agree you should look into VRF. Hope it goes well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Feb 2009 22:41:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-and-multiple-vlan-interface/m-p/1237475#M876233</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2009-02-18T22:41:37Z</dc:date>
    </item>
  </channel>
</rss>

