<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: multiple fwsm context on same vlan in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/multiple-fwsm-context-on-same-vlan/m-p/801100#M969995</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Stephane&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not sure i follow. Your original question was about not being able to share a vlan across contexts and i pointed out that you can. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as statics are concerned, yes you need to setup static translations because the classifier first looks at the vlan interface the packet comes in on but as the vlan is shared it then needs a translation to work out which context to use. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you explain what you mean regarding static routes ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 12 Sep 2007 06:14:10 GMT</pubDate>
    <dc:creator>Jon Marshall</dc:creator>
    <dc:date>2007-09-12T06:14:10Z</dc:date>
    <item>
      <title>multiple fwsm context on same vlan</title>
      <link>https://community.cisco.com/t5/network-security/multiple-fwsm-context-on-same-vlan/m-p/801095#M969990</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've noticed that for a reason, you cannot assign the same vlan onto multiple context within the FWSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way to go around this limitation? Does anybody know if this will be addressed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Stephane&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:07:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-fwsm-context-on-same-vlan/m-p/801095#M969990</guid>
      <dc:creator>stephg</dc:creator>
      <dc:date>2019-03-11T11:07:06Z</dc:date>
    </item>
    <item>
      <title>Re: multiple fwsm context on same vlan</title>
      <link>https://community.cisco.com/t5/network-security/multiple-fwsm-context-on-same-vlan/m-p/801096#M969991</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Stephane &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should be able to as the FWSM supports the concept of a shared vlan between contexts. On our production FWSM's we have a vlan for the outside interfaces that is shared between contexts so each outside interface has an IP address out of the same subnet. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Sep 2007 13:47:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-fwsm-context-on-same-vlan/m-p/801096#M969991</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-09-05T13:47:13Z</dc:date>
    </item>
    <item>
      <title>Re: multiple fwsm context on same vlan</title>
      <link>https://community.cisco.com/t5/network-security/multiple-fwsm-context-on-same-vlan/m-p/801097#M969992</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I thought that multiple contexts within the same fwsm share the same mac address. Is this correct&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Sep 2007 15:03:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-fwsm-context-on-same-vlan/m-p/801097#M969992</guid>
      <dc:creator>stephg</dc:creator>
      <dc:date>2007-09-05T15:03:37Z</dc:date>
    </item>
    <item>
      <title>Re: multiple fwsm context on same vlan</title>
      <link>https://community.cisco.com/t5/network-security/multiple-fwsm-context-on-same-vlan/m-p/801098#M969993</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Taken from our production FWSM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Admin context&lt;/P&gt;&lt;P&gt;=============&lt;/P&gt;&lt;P&gt;Interface vlan241 "outside", is up, line protocol is up&lt;/P&gt;&lt;P&gt;        MAC address 0015.624a.4780, MTU 1500&lt;/P&gt;&lt;P&gt;        IP address 10.181.107.132, subnet mask 255.255.255.128&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ebus context&lt;/P&gt;&lt;P&gt;============&lt;/P&gt;&lt;P&gt;Interface vlan241 "outside", is up, line protocol is up&lt;/P&gt;&lt;P&gt;        MAC address 0015.624a.4780, MTU 1500&lt;/P&gt;&lt;P&gt;        IP address 10.181.107.134, subnet mask 255.255.255.128&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So yes they do share the same mac-address bur remember that these are purely virtual interfaces. How the FWSM decides which context to send the traffic to is all to do with the classifier and indeed when you share a vlan you do have to be aware of how the FWSM clasifier works or it can be quite confusing &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Sep 2007 16:27:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-fwsm-context-on-same-vlan/m-p/801098#M969993</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-09-05T16:27:43Z</dc:date>
    </item>
    <item>
      <title>Re: multiple fwsm context on same vlan</title>
      <link>https://community.cisco.com/t5/network-security/multiple-fwsm-context-on-same-vlan/m-p/801099#M969994</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But using the classifier,  you had to  create a static nat to get it working. On top of it I would need to cascade contexts,  which I think does not work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why does'nt the fwsm now it's own ip's  and that you  have to NAT to get  it working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wouldn't static routes work&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Sep 2007 16:55:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-fwsm-context-on-same-vlan/m-p/801099#M969994</guid>
      <dc:creator>stephg</dc:creator>
      <dc:date>2007-09-11T16:55:31Z</dc:date>
    </item>
    <item>
      <title>Re: multiple fwsm context on same vlan</title>
      <link>https://community.cisco.com/t5/network-security/multiple-fwsm-context-on-same-vlan/m-p/801100#M969995</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Stephane&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not sure i follow. Your original question was about not being able to share a vlan across contexts and i pointed out that you can. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as statics are concerned, yes you need to setup static translations because the classifier first looks at the vlan interface the packet comes in on but as the vlan is shared it then needs a translation to work out which context to use. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you explain what you mean regarding static routes ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Sep 2007 06:14:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-fwsm-context-on-same-vlan/m-p/801100#M969995</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-09-12T06:14:10Z</dc:date>
    </item>
  </channel>
</rss>

