<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Shared Interface between FWSM Contexts in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/shared-interface-between-fwsm-contexts/m-p/1081397#M915686</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Right sorry, I meant shared vlans.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In an msfc-outside config, I want to have a switch connect into active context1 on vlan 5. I want another switch connect into context2 on vlan 6 from another switch. Now I want for both of these contexts to share "vlan 10".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Keep i n mind that Active context1 will be on 6506-1 and Active context2 will be on 6506-2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So my question is, can I setup a shared vlan for use between these 2 contexts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 30 Jul 2008 16:34:56 GMT</pubDate>
    <dc:creator>cisconoobie</dc:creator>
    <dc:date>2008-07-30T16:34:56Z</dc:date>
    <item>
      <title>Shared Interface between FWSM Contexts</title>
      <link>https://community.cisco.com/t5/network-security/shared-interface-between-fwsm-contexts/m-p/1081395#M915683</link>
      <description>&lt;P&gt;Is it possible to setup an Active/Active FWSM Configuration where there is a shared interface between both Active contexts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There will be 2 x 6506's with a FWSM each. I want to have an Active Context on each FWSM in the 6506's. And I want to make a shared interface between these active/active contexts across both 6506's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Possible?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:22:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/shared-interface-between-fwsm-contexts/m-p/1081395#M915683</guid>
      <dc:creator>cisconoobie</dc:creator>
      <dc:date>2019-03-11T13:22:43Z</dc:date>
    </item>
    <item>
      <title>Re: Shared Interface between FWSM Contexts</title>
      <link>https://community.cisco.com/t5/network-security/shared-interface-between-fwsm-contexts/m-p/1081396#M915684</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What do you mean by shared interfaces? YOu share interfaces because you are falling short of phyiscal interfaces, there is no such thing on the FWSM. Just VLANS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Jul 2008 14:03:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/shared-interface-between-fwsm-contexts/m-p/1081396#M915684</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-07-30T14:03:11Z</dc:date>
    </item>
    <item>
      <title>Re: Shared Interface between FWSM Contexts</title>
      <link>https://community.cisco.com/t5/network-security/shared-interface-between-fwsm-contexts/m-p/1081397#M915686</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Right sorry, I meant shared vlans.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In an msfc-outside config, I want to have a switch connect into active context1 on vlan 5. I want another switch connect into context2 on vlan 6 from another switch. Now I want for both of these contexts to share "vlan 10".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Keep i n mind that Active context1 will be on 6506-1 and Active context2 will be on 6506-2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So my question is, can I setup a shared vlan for use between these 2 contexts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Jul 2008 16:34:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/shared-interface-between-fwsm-contexts/m-p/1081397#M915686</guid>
      <dc:creator>cisconoobie</dc:creator>
      <dc:date>2008-07-30T16:34:56Z</dc:date>
    </item>
    <item>
      <title>Re: Shared Interface between FWSM Contexts</title>
      <link>https://community.cisco.com/t5/network-security/shared-interface-between-fwsm-contexts/m-p/1081398#M915688</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can only share it if interfaces are in routed mode. Normally only outside interfaces can be shared because of the FWSM's single MAC address limitation &amp;amp; Static statement requirement.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to use static NAT statements as In case of shared interfaces. FWSM's "Classifier" intercepts the traffic and depending on the destination IP hands the traffic over to the appropriated context.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Syed Iftekhar Ahmed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Jul 2008 17:21:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/shared-interface-between-fwsm-contexts/m-p/1081398#M915688</guid>
      <dc:creator>Syed Iftekhar Ahmed</dc:creator>
      <dc:date>2008-07-30T17:21:52Z</dc:date>
    </item>
    <item>
      <title>Re: Shared Interface between FWSM Contexts</title>
      <link>https://community.cisco.com/t5/network-security/shared-interface-between-fwsm-contexts/m-p/1081399#M915690</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can find some examples here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/fwsm/fwsm32/configuration/guide/exampl_f.html#wp1049516" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/fwsm/fwsm32/configuration/guide/exampl_f.html#wp1049516&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jul 2008 01:05:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/shared-interface-between-fwsm-contexts/m-p/1081399#M915690</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-07-31T01:05:23Z</dc:date>
    </item>
    <item>
      <title>Re: Shared Interface between FWSM Contexts</title>
      <link>https://community.cisco.com/t5/network-security/shared-interface-between-fwsm-contexts/m-p/1081400#M915692</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you both so much for the responses. Please take a look at my diagram of what I want to accomplish. I want to be able to access the Mail servers, DNS, filers, etc from both vlans.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically I want to be able to share "vlan 20", between C-1 (Context 1) and C-2 (Context 2)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to be able to connect to vlan 20 from vlan 10 and vlan 30 at any time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From what you said, I can only share the Outside Vlan &amp;amp; Interface but I cannot share the inside vlan, in my case vlan 20.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jul 2008 14:49:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/shared-interface-between-fwsm-contexts/m-p/1081400#M915692</guid>
      <dc:creator>cisconoobie</dc:creator>
      <dc:date>2008-07-31T14:49:19Z</dc:date>
    </item>
    <item>
      <title>Re: Shared Interface between FWSM Contexts</title>
      <link>https://community.cisco.com/t5/network-security/shared-interface-between-fwsm-contexts/m-p/1081401#M915694</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are right. &lt;/P&gt;&lt;P&gt;As I said the decision to pick Context is made on the "Destination address" defined  in a NAT statement.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For your outgoing traffic (from vlan 20) hitting internet. It would be practically impossible to  define NAT statements for internet Hosts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One option here would be to introduce two VRFs between  vlan 20 and the two FWSM contexts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Syed Iftekhar Ahmed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jul 2008 16:55:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/shared-interface-between-fwsm-contexts/m-p/1081401#M915694</guid>
      <dc:creator>Syed Iftekhar Ahmed</dc:creator>
      <dc:date>2008-07-31T16:55:50Z</dc:date>
    </item>
  </channel>
</rss>

