<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Contexts on FWSM!!!!! in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/contexts-on-fwsm/m-p/1103533#M914391</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Glenn&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you post a jpeg instead of a visio ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 18 Aug 2008 18:55:11 GMT</pubDate>
    <dc:creator>Jon Marshall</dc:creator>
    <dc:date>2008-08-18T18:55:11Z</dc:date>
    <item>
      <title>Contexts on FWSM!!!!!</title>
      <link>https://community.cisco.com/t5/network-security/contexts-on-fwsm/m-p/1103532#M914390</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;I have the following problem&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am working with security contexts on a FWSM installed on a cat 6500&lt;/P&gt;&lt;P&gt;(I strongly recommend that you take a look at the topology diagram at this point)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My problem is that I can't make server SIRE_APP located on DMZ_SIRE&lt;/P&gt;&lt;P&gt;to communicate with any other host on any other VLAN UNLESS&lt;/P&gt;&lt;P&gt;i manually configure the VLANS I want to communicate with on the CAT 6500 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for instance....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In order for server SIRE_APP (172.29.2.5) (VLAN 11 --&amp;gt;172.29.2.0) to communicate with server DNSin (172.29.1.2) (VLAN4 --&amp;gt;172.29.1.0)&lt;/P&gt;&lt;P&gt;i have to manually enter the following lines on the CAT 6500&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;++++++++++++++++++++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;interface Vlan11&lt;/P&gt;&lt;P&gt; description DMZ_SIRE (configured on context EXTRA)&lt;/P&gt;&lt;P&gt; ip address 172.29.2.254 255.255.255.0&lt;/P&gt;&lt;P&gt; no shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan4&lt;/P&gt;&lt;P&gt; description DMZ (configured on context EXTRA)&lt;/P&gt;&lt;P&gt; ip address 172.29.1.254 255.255.255.0&lt;/P&gt;&lt;P&gt; no shutdown&lt;/P&gt;&lt;P&gt;+++++++++++++++++++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then I have to manually change the SIRE_APP server's  default gateway to point to&lt;/P&gt;&lt;P&gt;ip 172.29.2.254 (vlan 11) configured on the CAT 6500 instead of pointing&lt;/P&gt;&lt;P&gt;to the ip 172.29.2.1 (configured as an interface on contect EXTRA)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BUT if I do this ALL other hosts on ANY other vlans can't communicate with servers on the DMZ (VLAN4)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Meanwhile.... &lt;/P&gt;&lt;P&gt;NONE of this is (or was necessary) in order for servers on VALN 4&lt;/P&gt;&lt;P&gt;DNSin, OASin to communicate with hosts on any other VLANS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have setup CAPTURES (raw-data &amp;amp; asp-drop types) but the problem is not an access-list, I have try several NATs but still the same...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have attached the run config for context EXTRA, context INTRA and context system (CONTEXTS.txt)&lt;/P&gt;&lt;P&gt;and relevan info on the running-config for the CAT 6500 (CAT 6500 with changes)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll appreciate any help on this issue&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Glenn&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:32:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/contexts-on-fwsm/m-p/1103532#M914390</guid>
      <dc:creator>glenn.guzman</dc:creator>
      <dc:date>2019-03-11T13:32:25Z</dc:date>
    </item>
    <item>
      <title>Re: Contexts on FWSM!!!!!</title>
      <link>https://community.cisco.com/t5/network-security/contexts-on-fwsm/m-p/1103533#M914391</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Glenn&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you post a jpeg instead of a visio ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Aug 2008 18:55:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/contexts-on-fwsm/m-p/1103533#M914391</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2008-08-18T18:55:11Z</dc:date>
    </item>
    <item>
      <title>Re: Contexts on FWSM!!!!!</title>
      <link>https://community.cisco.com/t5/network-security/contexts-on-fwsm/m-p/1103534#M914392</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You don't have a static from DMZ_SIRE to DMZ configured.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you getting xlate errors in the log of extra or the admin context?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try adding a static and pinging.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Aug 2008 19:52:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/contexts-on-fwsm/m-p/1103534#M914392</guid>
      <dc:creator>a-ford</dc:creator>
      <dc:date>2008-08-18T19:52:42Z</dc:date>
    </item>
  </channel>
</rss>

