<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FWSM setup in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fwsm-setup/m-p/1045852#M896682</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;even if its named "inside" syed?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 09 Sep 2008 17:55:47 GMT</pubDate>
    <dc:creator>joe19366</dc:creator>
    <dc:date>2008-09-09T17:55:47Z</dc:date>
    <item>
      <title>FWSM setup</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-setup/m-p/1045849#M896676</link>
      <description>&lt;P&gt;We placed a FWSM in our 6513 to replace our external PIX525. I'm able to session into the FWSM. We are not ready to switch over as yet. I just want to work with the FWSM a bit and get things ready. I created a VLAN15 on the 6513 and presented it to the FWSM. I created an interface and assigned an IP subnet on the 6513. I sessioned into the FWSM and assigned the presented VLAN an IP address. I named it inside and gave it a security level of 100. I setup a laptop on the VLAN and gave it an IP address on that subnet and added an icmp statement to allow the lpatop to ping the inside interface on the FWSM. Works. I added a telnet statement to the FWSM for the laptop. I can't telnet to the FWSM. I also tried enabling http for the laptop and that doesn't work as well. Not sure what I'm missing. I have not added any SVI outside interface to the FMSM as yet since we are not ready to switch over from the PIX. FWSM shows version 2.3(4). We are using only static NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have multiple VLANs on the 6513 that will all use the same outside interface on the FWSM. The VLANs route to each other inside the 6513. Some VLANs have more then one subnet defined as secondary on there interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:41:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-setup/m-p/1045849#M896676</guid>
      <dc:creator>cef2lion2</dc:creator>
      <dc:date>2019-03-11T13:41:37Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM setup</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-setup/m-p/1045850#M896678</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Let's see your configs (you can attach them here as text files)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have chosen "MSFC Inside" as your deployment design model. Microsoft actually has the best FWSM design guide on google; weird huh?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.microsoft.com/technet/solutionaccelerators/wssra/raguide/FirewallServices/igfspg_4.mspx" target="_blank"&gt;http://www.microsoft.com/technet/solutionaccelerators/wssra/raguide/FirewallServices/igfspg_4.mspx&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway, you will not then ALSO create SVI's on your MSFC, otherwise traffic could then route around the MSFC! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;perhaps you meant SVI in a VRF? either way normally we just use a few ports in a VLAN on the 6500 with NO SVI as "outside vlan" ports where the FWSM outside ip interface meet border routers, etc. when using the MSFC "inside" model described on MSFT's link.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The concept of where to place the MSFC can be confusing but that doc clears it up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let us know if we can be of help as you move forward.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Joe&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Sep 2008 17:47:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-setup/m-p/1045850#M896678</guid>
      <dc:creator>joe19366</dc:creator>
      <dc:date>2008-09-09T17:47:19Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM setup</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-setup/m-p/1045851#M896681</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Telnet doesn't not work on the least secured interface. If you have configured just one interface then it is he least secure one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Use SSH and it will work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Syed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Sep 2008 17:48:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-setup/m-p/1045851#M896681</guid>
      <dc:creator>Syed Iftekhar Ahmed</dc:creator>
      <dc:date>2008-09-09T17:48:41Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM setup</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-setup/m-p/1045852#M896682</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;even if its named "inside" syed?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Sep 2008 17:55:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-setup/m-p/1045852#M896682</guid>
      <dc:creator>joe19366</dc:creator>
      <dc:date>2008-09-09T17:55:47Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM setup</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-setup/m-p/1045853#M896683</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes. Even if its inside (provided there is no high security interface available). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Key point is Telnet is not possible to the "lowest security level" interface.With just one interface defined it will be the lowest security interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Syed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Sep 2008 19:20:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-setup/m-p/1045853#M896683</guid>
      <dc:creator>Syed Iftekhar Ahmed</dc:creator>
      <dc:date>2008-09-09T19:20:56Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM setup</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-setup/m-p/1045854#M896684</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes. Even if its inside (provided there is no high security interface available). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Key point is Telnet is not possible to the "lowest security level" interface.With just one interface defined it will be the lowest security interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Syed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Sep 2008 19:23:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-setup/m-p/1045854#M896684</guid>
      <dc:creator>Syed Iftekhar Ahmed</dc:creator>
      <dc:date>2008-09-09T19:23:36Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM setup</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-setup/m-p/1045855#M896685</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the information. Will try SSH and or create a temp outside interface with lower security level. Just want another means to admin the FWSM besides sessioning into it from the 6513.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think in our scenario we would want the MSFC inside. What commands place the MSFC on the inside or out? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Sep 2008 19:41:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-setup/m-p/1045855#M896685</guid>
      <dc:creator>cef2lion2</dc:creator>
      <dc:date>2008-09-09T19:41:19Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM setup</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-setup/m-p/1045856#M896686</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Create an SVI for the vlan connecting FWSM on the inside interface. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure that you dont have SVIs on vlans connected to insid e&amp;amp; outside interface. Otherwise you will end up bypassing FWSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Syed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Sep 2008 19:52:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-setup/m-p/1045856#M896686</guid>
      <dc:creator>Syed Iftekhar Ahmed</dc:creator>
      <dc:date>2008-09-09T19:52:52Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM setup</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-setup/m-p/1045857#M896687</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for tip on the SVIs. I created the outside interface with security level of 0 and I can now telnet into the FWSM inside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Sep 2008 19:58:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-setup/m-p/1045857#M896687</guid>
      <dc:creator>cef2lion2</dc:creator>
      <dc:date>2008-09-09T19:58:56Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM setup</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-setup/m-p/1045858#M896689</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;to reach the contexts themselves without using telnet/ssh you can just&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;session slot 4 proc 1 on the 6513 &lt;/P&gt;&lt;P&gt;(where slot 4 is the location of the FWSM).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you will then be in the SYSTEM context.&lt;/P&gt;&lt;P&gt;from there you can type&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;changeto context wan&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and you will be logged into the virtual-fw context named "wan".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See this doc for more information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/modules/ps2706/products_configuration_example09186a00809bfce4.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/modules/ps2706/products_configuration_example09186a00809bfce4.shtml&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Sep 2008 19:59:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-setup/m-p/1045858#M896689</guid>
      <dc:creator>joe19366</dc:creator>
      <dc:date>2008-09-09T19:59:58Z</dc:date>
    </item>
  </channel>
</rss>

