<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FWSM Multiple context in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fwsm-multiple-context/m-p/1172713#M877224</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here you go - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/fwsm/fwsm32/configuration/guide/exampl_f.html#wp1029314" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/fwsm/fwsm32/configuration/guide/exampl_f.html#wp1029314&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 26 Jan 2009 17:51:18 GMT</pubDate>
    <dc:creator>Jon Marshall</dc:creator>
    <dc:date>2009-01-26T17:51:18Z</dc:date>
    <item>
      <title>FWSM Multiple context</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-multiple-context/m-p/1172710#M877219</link>
      <description>&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any FWSM multiple context configuration example with 'shared ingress Vlan interface'.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 14:42:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-multiple-context/m-p/1172710#M877219</guid>
      <dc:creator>cisco_lite</dc:creator>
      <dc:date>2019-03-11T14:42:07Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM Multiple context</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-multiple-context/m-p/1172711#M877220</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When you say shared ingress vlan do you mean that each context shares a vlan for it's outside interfaces ie. each context uses an IP address from the same subnet on it's outside interface ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also is it safe to assume multiple context routed mode ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Finally, which version of FWSM software ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Jan 2009 17:39:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-multiple-context/m-p/1172711#M877220</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2009-01-26T17:39:11Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM Multiple context</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-multiple-context/m-p/1172712#M877222</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"When you say shared ingress vlan do you mean that each context shares a vlan for it's outside interfaces ie. each context uses an IP address from the same subnet on it's outside interface ? "&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, that is what I meant. &lt;/P&gt;&lt;P&gt;The multiple context shall be in routed mode. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWSM version 3.2(2)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Jan 2009 17:45:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-multiple-context/m-p/1172712#M877222</guid>
      <dc:creator>cisco_lite</dc:creator>
      <dc:date>2009-01-26T17:45:45Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM Multiple context</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-multiple-context/m-p/1172713#M877224</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here you go - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/fwsm/fwsm32/configuration/guide/exampl_f.html#wp1029314" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/fwsm/fwsm32/configuration/guide/exampl_f.html#wp1029314&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Jan 2009 17:51:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-multiple-context/m-p/1172713#M877224</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2009-01-26T17:51:18Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM Multiple context</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-multiple-context/m-p/1172714#M877227</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Jon. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Couple more questions&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Is NAT a condition to use multiple context with shared outside interface&lt;/P&gt;&lt;P&gt;2. Can IDSM be deployed to FWSM in multiple context. I believe If I failover single FWSM context to redundant Cat6500 chassis, IDSM will not work because IDSM can be active against one physical FWSM only. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Jan 2009 18:03:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-multiple-context/m-p/1172714#M877227</guid>
      <dc:creator>cisco_lite</dc:creator>
      <dc:date>2009-01-26T18:03:08Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM Multiple context</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-multiple-context/m-p/1172715#M877228</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) That's a very good question. When you share a vlan between contexts then the FWSM classifier comes into play. You need to have a read of this section. Sharing the same vlan for outside contexts is the most common approach so it is less problematic - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/fwsm/fwsm32/configuration/guide/contxt_f.html#wp1124236" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/fwsm/fwsm32/configuration/guide/contxt_f.html#wp1124236&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have any more questions on this please come back.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Unfortunately can't really help you on this as i have no real experience with the IDSM. I have used CSM-S modules (load-balancers) in conjunction with the FWSM's and they work in failover mode but i wouldn't want to say if this is possible with the IDSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Jan 2009 18:22:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-multiple-context/m-p/1172715#M877228</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2009-01-26T18:22:14Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM Multiple context</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-multiple-context/m-p/1172716#M877229</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jon, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my case all the NAT'ing is done on perimeter firewall and not FWSM. Traffic from firewall is routed to MSFC and then FWSM. So there is a single outside interface on FWSM, where the destination IP is already NAT'ed and should belong to one of the contexts (unique IP address). My understanding is that classifier would 'not' be required in the above scenario. Please advise.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Topology:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA-&amp;gt;MSFC-&amp;gt;FWSM-&amp;gt;ACE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Jan 2009 18:35:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-multiple-context/m-p/1172716#M877229</guid>
      <dc:creator>cisco_lite</dc:creator>
      <dc:date>2009-01-26T18:35:22Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM Multiple context</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-multiple-context/m-p/1172717#M877230</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Okay, i'm a little confused :-). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You say there is a single outside interface on FWSM but we were talking about multiple contexts using the same vlan for outside interfaces ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Assuming you are talking about a single context then note this from the link i sent -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;"Because the classifier relies on active NAT sessions to classify the destination addresses to a context, the classifier is limited by how you can configure NAT. If you do not want to perform NAT, you must use unique interfaces."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So you need NAT but all this means is you need to setup static translations ie. you don't need to actually change the IP address eg.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 192.168.5.0 192.168.5.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does this make sense or have i misunderstood your topology ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Jan 2009 18:44:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-multiple-context/m-p/1172717#M877230</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2009-01-26T18:44:14Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM Multiple context</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-multiple-context/m-p/1172718#M877232</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ok. I meant single shared vlan by outside across multiple contexts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I understand NAT to be a condition (even though to same IP) for multiple contexts to work in the given topology and requirement.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon, if you don't mind could you please provide your valuable inputs on the below post in 'Lan,Switching &amp;amp; Routing'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Network%20Infrastructure&amp;amp;topic=LAN%2C%20Switching%20and%20Routing&amp;amp;topicID=.ee71a04&amp;amp;fromOutline=&amp;amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cc2d744" target="_blank"&gt;http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Network%20Infrastructure&amp;amp;topic=LAN%2C%20Switching%20and%20Routing&amp;amp;topicID=.ee71a04&amp;amp;fromOutline=&amp;amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cc2d744&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Jan 2009 19:49:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-multiple-context/m-p/1172718#M877232</guid>
      <dc:creator>cisco_lite</dc:creator>
      <dc:date>2009-01-26T19:49:32Z</dc:date>
    </item>
  </channel>
</rss>

