<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issue with FWSM configuration in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/issue-with-fwsm-configuration/m-p/920438#M974502</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I from my switch i am not able to ping the switch vlan i.e 100. It is showing down to me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sanjoy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 25 Sep 2007 16:59:08 GMT</pubDate>
    <dc:creator>sanjoy2006</dc:creator>
    <dc:date>2007-09-25T16:59:08Z</dc:date>
    <item>
      <title>Issue with FWSM configuration</title>
      <link>https://community.cisco.com/t5/network-security/issue-with-fwsm-configuration/m-p/920432#M974496</link>
      <description>&lt;P&gt;I have configure on switch 6509&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;firewall module 4 vlan-group 1&lt;/P&gt;&lt;P&gt;firewall vlan-group 1  2-100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan100&lt;/P&gt;&lt;P&gt; description ### Outgoing ####&lt;/P&gt;&lt;P&gt; ip address 172.31.254.1 255.255.255.248&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And below are FWSM conf &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWSM# sh run&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;FWSM Version 3.1(3) &amp;lt;system&amp;gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;resource acl-partition 12&lt;/P&gt;&lt;P&gt;hostname FWSM&lt;/P&gt;&lt;P&gt;enable password xxx&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan50&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan51&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan52&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan100&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;passwd xxx&lt;/P&gt;&lt;P&gt;class default&lt;/P&gt;&lt;P&gt;  limit-resource All 0&lt;/P&gt;&lt;P&gt;  limit-resource IPSec 5&lt;/P&gt;&lt;P&gt;  limit-resource Mac-addresses 65535&lt;/P&gt;&lt;P&gt;  limit-resource ASDM 5&lt;/P&gt;&lt;P&gt;  limit-resource SSH 5&lt;/P&gt;&lt;P&gt;  limit-resource Telnet 5&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class gold&lt;/P&gt;&lt;P&gt;  limit-resource rate Conns 2000&lt;/P&gt;&lt;P&gt;  limit-resource Conns 20000&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class silver&lt;/P&gt;&lt;P&gt;  limit-resource rate Conns 1000&lt;/P&gt;&lt;P&gt;  limit-resource Conns 10000&lt;/P&gt;&lt;P&gt;  limit-resource ASDM 3.0%&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class bronze&lt;/P&gt;&lt;P&gt;  limit-resource rate Conns 500&lt;/P&gt;&lt;P&gt;  limit-resource Conns 5000&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;no failover&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;admin-context admin&lt;/P&gt;&lt;P&gt;context admin&lt;/P&gt;&lt;P&gt;  member default&lt;/P&gt;&lt;P&gt;  allocate-interface Vlan100&lt;/P&gt;&lt;P&gt;  allocate-interface Vlan50&lt;/P&gt;&lt;P&gt;  allocate-interface Vlan51&lt;/P&gt;&lt;P&gt;  allocate-interface Vlan52&lt;/P&gt;&lt;P&gt;  config-url disk:/admin.cfg&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;context customer1&lt;/P&gt;&lt;P&gt;  description This is the context for customer 1&lt;/P&gt;&lt;P&gt;  member gold&lt;/P&gt;&lt;P&gt;  allocate-interface Vlan100&lt;/P&gt;&lt;P&gt;  allocate-interface Vlan50&lt;/P&gt;&lt;P&gt;  config-url disk:/context1.cfg&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;context customer2&lt;/P&gt;&lt;P&gt;  description This is the context for customer 2&lt;/P&gt;&lt;P&gt;  allocate-interface Vlan100&lt;/P&gt;&lt;P&gt;  allocate-interface Vlan51&lt;/P&gt;&lt;P&gt;  config-url disk:/context2.cfg&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;context customer3&lt;/P&gt;&lt;P&gt;  description This is the context for customer 3&lt;/P&gt;&lt;P&gt;  allocate-interface Vlan100&lt;/P&gt;&lt;P&gt;  allocate-interface Vlan52&lt;/P&gt;&lt;P&gt;  config-url disk:/context3.cfg&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;prompt hostname context&lt;/P&gt;&lt;P&gt;Cryptochecksum:xxx&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;FWSM#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But am not able to put ip address and nameif in my FWSM vlan interface.Kindly suggest where is issue&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:16:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/issue-with-fwsm-configuration/m-p/920432#M974496</guid>
      <dc:creator>sanjoy2006</dc:creator>
      <dc:date>2019-03-11T11:16:08Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with FWSM configuration</title>
      <link>https://community.cisco.com/t5/network-security/issue-with-fwsm-configuration/m-p/920433#M974497</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where are you trying to configure the nameif command ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to do this within the context. So choose the context you want to configure and from the enable prompt &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWSM# change context context2 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This should put you into context2 and from there you can configure the nameif, NAT, access-lists etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Sep 2007 19:29:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/issue-with-fwsm-configuration/m-p/920433#M974497</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-09-24T19:29:07Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with FWSM configuration</title>
      <link>https://community.cisco.com/t5/network-security/issue-with-fwsm-configuration/m-p/920434#M974498</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now am able to enter in each context and got for ip configuration command but it will not showing in main running config.&lt;/P&gt;&lt;P&gt;can u send me any template to use in multiple mode configuration and how to map with my IOS vlan.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgd&lt;/P&gt;&lt;P&gt;Sanjoy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Sep 2007 08:20:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/issue-with-fwsm-configuration/m-p/920434#M974498</guid>
      <dc:creator>sanjoy2006</dc:creator>
      <dc:date>2007-09-25T08:20:15Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with FWSM configuration</title>
      <link>https://community.cisco.com/t5/network-security/issue-with-fwsm-configuration/m-p/920435#M974499</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sanjoy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not sure what you mean about running config. When you use multiple contexts on the FWSM you have to change to each context to see the running config for that context. They are in effect separate firewalls. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In your original post your configuration was in system execution space ie. this is where you define your virtual firewalls, allocate vlans, set resources etc. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once you have setup a context in system execution space you then have to change to the context to configure the firewall. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not sure what you mean by map IOS vlan. Could you clarify.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Sep 2007 09:34:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/issue-with-fwsm-configuration/m-p/920435#M974499</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-09-25T09:34:09Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with FWSM configuration</title>
      <link>https://community.cisco.com/t5/network-security/issue-with-fwsm-configuration/m-p/920436#M974500</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Suppose in main switch configuration (IOS)there is vlan 100 which is my traffic outgoing .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I have configured 3 context and 50,51,52,99 is my inside vlan and 100 is my common outside vlan .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now when in IOS one vlan 100 is enable no issue but when we genarating vla 50 or 51 &lt;/P&gt;&lt;P&gt;error comming &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DC_Core_Switch_2(config-if)#no sh&lt;/P&gt;&lt;P&gt;Forcing SVI 50 to stay shutdown (SVI 100 tied to line card in slot 4.)&lt;/P&gt;&lt;P&gt;DC_Core_Switch_2(config-if)#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I haven't configure "firewall multiple-vlan-interfaces"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configure "firewall module 4 vlan-group 1&lt;/P&gt;&lt;P&gt;firewall vlan-group 1  50-100"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWSM# changeto conte&lt;/P&gt;&lt;P&gt;FWSM# changeto context admin&lt;/P&gt;&lt;P&gt;FWSM/admin#&lt;/P&gt;&lt;P&gt;FWSM/admin#&lt;/P&gt;&lt;P&gt;FWSM/admin# sh run&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;FWSM Version 3.1(3) &lt;CONTEXT&gt;&lt;/CONTEXT&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname FWSM&lt;/P&gt;&lt;P&gt;domain-name show&lt;/P&gt;&lt;P&gt;enable password xxx&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan100&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 172.29.254.2 255.255.255.248&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan99&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 172.29.254.66 255.255.255.240&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;passwd xxx&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;nat-control&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 172.29.254.1 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00&lt;/P&gt;&lt;P&gt;timeout mgcp-pat 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;  inspect dns maximum-length 512&lt;/P&gt;&lt;P&gt;  inspect ftp&lt;/P&gt;&lt;P&gt;  inspect h323 h225&lt;/P&gt;&lt;P&gt;  inspect h323 ras&lt;/P&gt;&lt;P&gt;  inspect netbios&lt;/P&gt;&lt;P&gt;  inspect rsh&lt;/P&gt;&lt;P&gt;  inspect skinny&lt;/P&gt;&lt;P&gt;  inspect smtp&lt;/P&gt;&lt;P&gt;  inspect sqlnet&lt;/P&gt;&lt;P&gt;  inspect sunrpc&lt;/P&gt;&lt;P&gt;  inspect tftp&lt;/P&gt;&lt;P&gt;  inspect sip&lt;/P&gt;&lt;P&gt;  inspect xdmcp&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;Cryptochecksum:xxx&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;FWSM/admin#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but am not clear how to map main vlan which I configure in switch and which one is on my FWSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgd&lt;/P&gt;&lt;P&gt;Sanjoy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Sep 2007 10:29:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/issue-with-fwsm-configuration/m-p/920436#M974500</guid>
      <dc:creator>sanjoy2006</dc:creator>
      <dc:date>2007-09-25T10:29:13Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with FWSM configuration</title>
      <link>https://community.cisco.com/t5/network-security/issue-with-fwsm-configuration/m-p/920437#M974501</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sanjoy &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any vlan that is meant to be on the inside of the FWSM should not have an SVI (Layer 3 interface) on the switch. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If vlan 100 is the outside vlan this will have an SVI on the 6500 switch. If you then added an SVI for vlan 50 which is supposed to be the inside interface for one of your contexts, traffic would be routed around the FWSM from vlan 100 to vlan 50. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are right to not enable firewall multiple-vlan-interfaces for this setup altho we have in our FWSM but for a different purpose. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember you need  vlans 50,51,52,99  created at layer 2 on the switch but you do not want an SVI on the switch for these vlans. Their Layer 3 interface will be on the FWSM within their respective contexts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also note that with multiple context mode you will need static routes on your 6500 to get to the subnets behind the FWSM eg from your config above on the 6500&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip route 172.29.254.64 255.255.255.240 172.29.254.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does this make sense ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Sep 2007 11:03:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/issue-with-fwsm-configuration/m-p/920437#M974501</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-09-25T11:03:39Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with FWSM configuration</title>
      <link>https://community.cisco.com/t5/network-security/issue-with-fwsm-configuration/m-p/920438#M974502</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I from my switch i am not able to ping the switch vlan i.e 100. It is showing down to me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sanjoy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Sep 2007 16:59:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/issue-with-fwsm-configuration/m-p/920438#M974502</guid>
      <dc:creator>sanjoy2006</dc:creator>
      <dc:date>2007-09-25T16:59:08Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with FWSM configuration</title>
      <link>https://community.cisco.com/t5/network-security/issue-with-fwsm-configuration/m-p/920439#M974503</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ya , I got it .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dear Jon ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am attaching full configuration below because still now am not getting my outside vlan 100 UP  ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I AM NOT GETTING WHERE ACTUALY AM DOING MISTAKE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;=========== SWITCH CONF ========&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;svclc vlan-group 1  50-100&lt;/P&gt;&lt;P&gt;firewall module 4 vlan-group 1&lt;/P&gt;&lt;P&gt;firewall vlan-group 1  50-100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vlan 50&lt;/P&gt;&lt;P&gt; name customer1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;vlan 51&lt;/P&gt;&lt;P&gt; name customer2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;vlan 52&lt;/P&gt;&lt;P&gt; name customer3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan100&lt;/P&gt;&lt;P&gt; description ### Outgoing ####&lt;/P&gt;&lt;P&gt; ip address 172.29.254.1 255.255.255.240&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  ====FWSM SYSTEM CONF===&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;resource acl-partition 12&lt;/P&gt;&lt;P&gt;hostname FWSM&lt;/P&gt;&lt;P&gt;enable password 9jNfZuG3TC5tCVH0 encrypted&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan50&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan51&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan52&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan99&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan100&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;passwd 2KFQnbNIdI.2KYOU encrypted&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;admin-context admin&lt;/P&gt;&lt;P&gt;context admin&lt;/P&gt;&lt;P&gt;  allocate-interface Vlan100&lt;/P&gt;&lt;P&gt;  allocate-interface Vlan99&lt;/P&gt;&lt;P&gt;  allocate-acl-partition 0&lt;/P&gt;&lt;P&gt;  config-url disk:/admin.cfg&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;context customer1&lt;/P&gt;&lt;P&gt;  allocate-interface Vlan100&lt;/P&gt;&lt;P&gt;  allocate-interface Vlan50&lt;/P&gt;&lt;P&gt;  allocate-acl-partition 1&lt;/P&gt;&lt;P&gt;  config-url disk:/context1.cfg&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;context customer2&lt;/P&gt;&lt;P&gt;  allocate-interface Vlan100&lt;/P&gt;&lt;P&gt;  allocate-interface Vlan51&lt;/P&gt;&lt;P&gt;  allocate-acl-partition 2&lt;/P&gt;&lt;P&gt;  config-url disk:/context2.cfg&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;context customer3&lt;/P&gt;&lt;P&gt;  allocate-interface Vlan100&lt;/P&gt;&lt;P&gt;  allocate-interface Vlan52&lt;/P&gt;&lt;P&gt;  allocate-acl-partition 3&lt;/P&gt;&lt;P&gt;  config-url disk:/context3.cfg&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;=========== admin context ==&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWSM/admin# sh run&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;enable password 2KFQnbNIdI.2KYOU encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan100&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 172.29.254.2 255.255.255.240&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan99&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 172.29.254.66 255.255.255.240&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;passwd 2KFQnbNIdI.2KYOU encrypted&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;nat-control&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 172.29.254.1 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00&lt;/P&gt;&lt;P&gt;timeout mgcp-pat 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;FWSM/admin#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;====  CUSTOMER1 CONTEXT &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWSM/customer1#&lt;/P&gt;&lt;P&gt;FWSM/customer1# sh run&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan100&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 172.29.254.3 255.255.255.240&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan50&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 172.29.254.17 255.255.255.240&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;passwd 2KFQnbNIdI.2KYOU encrypted&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 172.29.254.1 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00&lt;/P&gt;&lt;P&gt;timeout mgcp-pat 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Sep 2007 20:48:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/issue-with-fwsm-configuration/m-p/920439#M974503</guid>
      <dc:creator>sanjoy2006</dc:creator>
      <dc:date>2007-09-25T20:48:05Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with FWSM configuration</title>
      <link>https://community.cisco.com/t5/network-security/issue-with-fwsm-configuration/m-p/920440#M974504</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sanjoy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you just confirm that you have created vlan 100 as a layer 2 vlan on your 6500 switch. if you do a "sh ip int br" on the 6500 is the vlan 100 interface up/up ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Sep 2007 21:05:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/issue-with-fwsm-configuration/m-p/920440#M974504</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-09-25T21:05:23Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with FWSM configuration</title>
      <link>https://community.cisco.com/t5/network-security/issue-with-fwsm-configuration/m-p/920441#M974505</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jon&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vlan 100 is not my l2 it's layer 3 because it's my outgoing int.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh ip int brief&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vlan100  172.29.254.1  YES manual down/down&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgd &lt;/P&gt;&lt;P&gt;Sanjoy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Sep 2007 04:26:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/issue-with-fwsm-configuration/m-p/920441#M974505</guid>
      <dc:creator>sanjoy2006</dc:creator>
      <dc:date>2007-09-26T04:26:16Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with FWSM configuration</title>
      <link>https://community.cisco.com/t5/network-security/issue-with-fwsm-configuration/m-p/920442#M974507</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot for ur great support from the begining my Switch (MSFC)vlan100 showing up now .&lt;/P&gt;&lt;P&gt;Vlan100  172.29.254.1  YES manual up up&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now we are able to ping from context too&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rgd&lt;/P&gt;&lt;P&gt;Sanjoy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Sep 2007 09:55:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/issue-with-fwsm-configuration/m-p/920442#M974507</guid>
      <dc:creator>sanjoy2006</dc:creator>
      <dc:date>2007-09-26T09:55:09Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with FWSM configuration</title>
      <link>https://community.cisco.com/t5/network-security/issue-with-fwsm-configuration/m-p/920443#M974508</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sanjoy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Glad to hear you got it working. Thanks for letting me know and i appreciate the ratings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Sep 2007 15:01:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/issue-with-fwsm-configuration/m-p/920443#M974508</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-09-27T15:01:21Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with FWSM configuration</title>
      <link>https://community.cisco.com/t5/network-security/issue-with-fwsm-configuration/m-p/920444#M974510</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry but I have a question ,I am not ablt to ping switch l3 vlan ip from customer context but able to ping fwsm outside ip of admin context and outside ip of other cotext too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is it ok or still now there is issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Sep 2007 02:04:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/issue-with-fwsm-configuration/m-p/920444#M974510</guid>
      <dc:creator>sanjoy2006</dc:creator>
      <dc:date>2007-09-28T02:04:23Z</dc:date>
    </item>
  </channel>
</rss>

