<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Transparent mode and failover. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/transparent-mode-and-failover/m-p/942231#M939411</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In transparent mode, all allowed traffic is passed, but only IP-traffic can be inspected. Normally BPDUs are blocked, but you want them through if using STP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In transparent failover mode, you definitely want STP, to eliminate problems when both FWs become active (should never happen, but...).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In standby mode, the FW does not pass any traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a failover link between active and standby FW, to carry FW status info. If you do stateful failover, the state-info is transferred too (on it's own VLAN). This is management traffic, no user data!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't know about ASA, but an FWSM allows up to 8 BVI-groups per context. An inside VLAN is connected to an outside VLAN by the transparent FW (this is called a BVI-group). Each BVI-group is completely isolated from each other. You need a router to get traffic between the BVI groups.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thr management interface is just for that. It also can carry traffic for AAA (eg. a connection to the radius server).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marcel&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 21 Apr 2008 07:19:13 GMT</pubDate>
    <dc:creator>mvandorp</dc:creator>
    <dc:date>2008-04-21T07:19:13Z</dc:date>
    <item>
      <title>Transparent mode and failover.</title>
      <link>https://community.cisco.com/t5/network-security/transparent-mode-and-failover/m-p/942229#M939409</link>
      <description>&lt;P&gt;Does an ASA in both transparent mode and standby state pass any type of traffic?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Paulo Roque&lt;/P&gt;&lt;P&gt;Network Engineer&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:30:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/transparent-mode-and-failover/m-p/942229#M939409</guid>
      <dc:creator>pauloroque</dc:creator>
      <dc:date>2019-03-11T12:30:14Z</dc:date>
    </item>
    <item>
      <title>Re: Transparent mode and failover.</title>
      <link>https://community.cisco.com/t5/network-security/transparent-mode-and-failover/m-p/942230#M939410</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Transparent firewall mode allows only two interfaces to pass through traffic; however, on the ASA adaptive security appliance, you can use the dedicated management interface (either the physical interface or a subinterface) as a third interface for management traffic. The mode is not configurable in this case and must always be management-only&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Apr 2008 20:39:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/transparent-mode-and-failover/m-p/942230#M939410</guid>
      <dc:creator />
      <dc:date>2008-04-17T20:39:21Z</dc:date>
    </item>
    <item>
      <title>Re: Transparent mode and failover.</title>
      <link>https://community.cisco.com/t5/network-security/transparent-mode-and-failover/m-p/942231#M939411</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In transparent mode, all allowed traffic is passed, but only IP-traffic can be inspected. Normally BPDUs are blocked, but you want them through if using STP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In transparent failover mode, you definitely want STP, to eliminate problems when both FWs become active (should never happen, but...).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In standby mode, the FW does not pass any traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a failover link between active and standby FW, to carry FW status info. If you do stateful failover, the state-info is transferred too (on it's own VLAN). This is management traffic, no user data!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't know about ASA, but an FWSM allows up to 8 BVI-groups per context. An inside VLAN is connected to an outside VLAN by the transparent FW (this is called a BVI-group). Each BVI-group is completely isolated from each other. You need a router to get traffic between the BVI groups.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thr management interface is just for that. It also can carry traffic for AAA (eg. a connection to the radius server).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marcel&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Apr 2008 07:19:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/transparent-mode-and-failover/m-p/942231#M939411</guid>
      <dc:creator>mvandorp</dc:creator>
      <dc:date>2008-04-21T07:19:13Z</dc:date>
    </item>
  </channel>
</rss>

