<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 6509 FWSM configuration in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/6509-fwsm-configuration/m-p/970887#M918324</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes you will see it listed. The vlan has to exist on the 6500 at Layer 2 so you can allocate it to the FWSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edit - just to clarify. You do a sh vlan on the switch not the MSFC. If you are running Native then "sh vlan" can be run from anywhere.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are running in hybrid "sh vlan" must be done from the switch prompt ie. not the MSFC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 17 Jun 2008 18:06:25 GMT</pubDate>
    <dc:creator>Jon Marshall</dc:creator>
    <dc:date>2008-06-17T18:06:25Z</dc:date>
    <item>
      <title>6509 FWSM configuration</title>
      <link>https://community.cisco.com/t5/network-security/6509-fwsm-configuration/m-p/970876#M918291</link>
      <description>&lt;P&gt;How can I configure a 6509 switch with a FWSM to use an outside address of 10.1.1.1 and a inside address of 192.168.1.1? I would like to create a NAT that will resolve to several servers on the inside. How do you configure the inside and outside interfaces to a port on the switch? I know you do it via vlans, but when I create the vlan does both vlans get assigned to the firewall vlan-group or just one?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:00:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/6509-fwsm-configuration/m-p/970876#M918291</guid>
      <dc:creator>wheeler930</dc:creator>
      <dc:date>2019-03-11T13:00:05Z</dc:date>
    </item>
    <item>
      <title>Re: 6509 FWSM configuration</title>
      <link>https://community.cisco.com/t5/network-security/6509-fwsm-configuration/m-p/970877#M918297</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the vlan is to be routed off the FWSM then you need to assign it to the FWSM via the firewall vlan-group ... command on the 6500. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So if vlan 10 is your inside vlan then yes you assign this to the FWSM. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If vlan 11 is your outside vlan and the FWSM has it's outside interface in this vlan and there is also a L3 SVI for vlan 11 on the MSFC then you don't need to allocate this to the FWSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See link for more config details:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;CommCmd=MB%3Fcmd%3Dpass_through%26location%3Doutline%40%5E1%40.2cbef1c1/5#selected_message" target="_blank"&gt;http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;CommCmd=MB%3Fcmd%3Dpass_through%26location%3Doutline%40%5E1%40.2cbef1c1/5#selected_message&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Jun 2008 19:20:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/6509-fwsm-configuration/m-p/970877#M918297</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2008-06-16T19:20:47Z</dc:date>
    </item>
    <item>
      <title>Re: 6509 FWSM configuration</title>
      <link>https://community.cisco.com/t5/network-security/6509-fwsm-configuration/m-p/970878#M918301</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, I believe I have it setup properly, but how do you setup a interface for the inside vlan. The outside vlan is the vlan on the MSFC, but where do you configure the interface for the inside vlan interface? Also from inside when i try to ping I get ????? any reason why?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Jun 2008 20:05:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/6509-fwsm-configuration/m-p/970878#M918301</guid>
      <dc:creator>wheeler930</dc:creator>
      <dc:date>2008-06-16T20:05:53Z</dc:date>
    </item>
    <item>
      <title>Re: 6509 FWSM configuration</title>
      <link>https://community.cisco.com/t5/network-security/6509-fwsm-configuration/m-p/970879#M918303</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;did you inlcude that vlan in the fwsm?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;like this on the 6500 box&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;firewall module 1 vlan-group 1&lt;/P&gt;&lt;P&gt;firewall vlan-group 1  96-990&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and than created that vlan on the fwsm?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jun 2008 13:48:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/6509-fwsm-configuration/m-p/970879#M918303</guid>
      <dc:creator>bitonw</dc:creator>
      <dc:date>2008-06-17T13:48:31Z</dc:date>
    </item>
    <item>
      <title>Re: 6509 FWSM configuration</title>
      <link>https://community.cisco.com/t5/network-security/6509-fwsm-configuration/m-p/970880#M918304</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, I did that. Maybe I am asking the wrong question. I am use to setting up PIX 515e, You have E0 and E1. Each interface is designated to be inside or outside. When using the 6509 the SVI, I am assuming is the outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the inside interface? and How is it configure to specify an interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jun 2008 13:57:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/6509-fwsm-configuration/m-p/970880#M918304</guid>
      <dc:creator>wheeler930</dc:creator>
      <dc:date>2008-06-17T13:57:03Z</dc:date>
    </item>
    <item>
      <title>Re: 6509 FWSM configuration</title>
      <link>https://community.cisco.com/t5/network-security/6509-fwsm-configuration/m-p/970881#M918306</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The SVI on your MSFC is not the outside interface of your FWSM. It should look something like this &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MSFC SVI (192.168.2.1)  -&amp;gt; (192.168.2.2) outside FWSM  inside (192.168.3.1 )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The outside interface of your FWSM is in the same vlan as the MSFC SVI. The inside interface is only on the FWSM ie. there is no L3 SVI for the inside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As for creating the outside and inside interfaces you would do this on the FWSM and is very similiar to what you would do on a standalone device. Attached is a basic getting started guide for the FWSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/modules/ps2706/products_configuration_example09186a00808b4d9f.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/modules/ps2706/products_configuration_example09186a00808b4d9f.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jun 2008 14:47:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/6509-fwsm-configuration/m-p/970881#M918306</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2008-06-17T14:47:40Z</dc:date>
    </item>
    <item>
      <title>Re: 6509 FWSM configuration</title>
      <link>https://community.cisco.com/t5/network-security/6509-fwsm-configuration/m-p/970882#M918309</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So, does the whole switch with the exception of the outside interface SVI, become the inside vlan?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How do you add systems to the inside vlan?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jun 2008 17:14:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/6509-fwsm-configuration/m-p/970882#M918309</guid>
      <dc:creator>wheeler930</dc:creator>
      <dc:date>2008-06-17T17:14:18Z</dc:date>
    </item>
    <item>
      <title>Re: 6509 FWSM configuration</title>
      <link>https://community.cisco.com/t5/network-security/6509-fwsm-configuration/m-p/970883#M918312</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"So, does the whole switch with the exception of the outside interface SVI, become the inside vlan?"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No it doesn't. The inside vlan is simply the vlan you have allocated to the inside interface on your FWSM. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So lets say you have vlans 10 - 20 on your 6500. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Until you allocate any of these vlans to the FWSM with the firewall vlan-group ... command they are just vlans on the 6500, nothing to do with the FWSM. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you then allocate vlan 11 as the inside vlan on the FWSM then all the other vlans 10,12 - 20 are still vlans on the 6500, nothing to do with the FWSM. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You add systems to the inside vlans by simply adding ports into that vlan. So if you have connected 2 servers to gi2/1 &amp;amp; gi2/1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;6500(config)# int range gi2/1 - 2&lt;/P&gt;&lt;P&gt;6500(config-if)# switchport access vlan 11&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These servers are now in vlan 11 and will be on the inside vlan of the FWSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jun 2008 17:23:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/6509-fwsm-configuration/m-p/970883#M918312</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2008-06-17T17:23:33Z</dc:date>
    </item>
    <item>
      <title>Re: 6509 FWSM configuration</title>
      <link>https://community.cisco.com/t5/network-security/6509-fwsm-configuration/m-p/970884#M918314</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Got you, man thanks. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So what you are saying is the vlan 11 will not have a SVI right?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jun 2008 17:34:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/6509-fwsm-configuration/m-p/970884#M918314</guid>
      <dc:creator>wheeler930</dc:creator>
      <dc:date>2008-06-17T17:34:42Z</dc:date>
    </item>
    <item>
      <title>Re: 6509 FWSM configuration</title>
      <link>https://community.cisco.com/t5/network-security/6509-fwsm-configuration/m-p/970885#M918316</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Correct, vlan 11 will not have an SVI on the 6500. This applies to all interfaces on the FWSM ie. DMZ's etc. except for the outside interface in your scenario which will have a L3 SVI on the 6500.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jun 2008 17:37:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/6509-fwsm-configuration/m-p/970885#M918316</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2008-06-17T17:37:27Z</dc:date>
    </item>
    <item>
      <title>Re: 6509 FWSM configuration</title>
      <link>https://community.cisco.com/t5/network-security/6509-fwsm-configuration/m-p/970886#M918318</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So if I do a sh vlan on the MSFC, should I see the "inside" vlan listed?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jun 2008 18:05:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/6509-fwsm-configuration/m-p/970886#M918318</guid>
      <dc:creator>wheeler930</dc:creator>
      <dc:date>2008-06-17T18:05:00Z</dc:date>
    </item>
    <item>
      <title>Re: 6509 FWSM configuration</title>
      <link>https://community.cisco.com/t5/network-security/6509-fwsm-configuration/m-p/970887#M918324</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes you will see it listed. The vlan has to exist on the 6500 at Layer 2 so you can allocate it to the FWSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edit - just to clarify. You do a sh vlan on the switch not the MSFC. If you are running Native then "sh vlan" can be run from anywhere.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are running in hybrid "sh vlan" must be done from the switch prompt ie. not the MSFC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jun 2008 18:06:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/6509-fwsm-configuration/m-p/970887#M918324</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2008-06-17T18:06:25Z</dc:date>
    </item>
    <item>
      <title>Re: 6509 FWSM configuration</title>
      <link>https://community.cisco.com/t5/network-security/6509-fwsm-configuration/m-p/970888#M918326</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I turned on rip passive and default on the inside, but I am not able to ping any systems on the inside. Any reason why?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jun 2008 18:31:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/6509-fwsm-configuration/m-p/970888#M918326</guid>
      <dc:creator>wheeler930</dc:creator>
      <dc:date>2008-06-17T18:31:48Z</dc:date>
    </item>
  </channel>
</rss>

