<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FWSM outside interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fwsm-outside-interface/m-p/776070#M984519</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;no, the client PCs are of different vlans with respect to their respective outside interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i dont have working config yet for this setup but here is my current config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nameif vlan325 internet security0&lt;/P&gt;&lt;P&gt;nameif vlan555 fwtest security0&lt;/P&gt;&lt;P&gt;nameif vlan327 inside security100&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit ip x.x.x.x [IP from inside] host y.y.y.y [PC1] &lt;/P&gt;&lt;P&gt;access-list internet_access_in extended permit ip host y.y.y.y [PC1] host x.x.x.x [IP from inside] &lt;/P&gt;&lt;P&gt;access-list fwtest_access_in extended permit ip any  &lt;/P&gt;&lt;P&gt;ip address inside &lt;/P&gt;&lt;P&gt;ip address internet &lt;/P&gt;&lt;P&gt;ip address fwtest &lt;/P&gt;&lt;P&gt;icmp permit any inside&lt;/P&gt;&lt;P&gt;icmp permit any internet&lt;/P&gt;&lt;P&gt;icmp permit any fwtest&lt;/P&gt;&lt;P&gt;no pdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (inside) 1 interface&lt;/P&gt;&lt;P&gt;global (internet) 1 interface&lt;/P&gt;&lt;P&gt;global (fwtest) 3 interface&lt;/P&gt;&lt;P&gt;global (bdoextranetout) 2 interface&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list inside_nat0_outbound&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;nat (internet) 1 access-list fwtest_nat0_outbound&lt;/P&gt;&lt;P&gt;nat (fwtest) 3 access-list bdoextranetin_pnat_outbound_V3&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface inside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface internet&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface fwtest&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 12 Jul 2007 06:52:31 GMT</pubDate>
    <dc:creator>dennisopiso</dc:creator>
    <dc:date>2007-07-12T06:52:31Z</dc:date>
    <item>
      <title>FWSM outside interface</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-outside-interface/m-p/776066#M984515</link>
      <description>&lt;P&gt;i'm trying to make two outside interfaces in FWSM to talk to each other and i cant seem to make it work.  any idea or sample configuration please&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 10:43:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-outside-interface/m-p/776066#M984515</guid>
      <dc:creator>dennisopiso</dc:creator>
      <dc:date>2019-03-11T10:43:49Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM outside interface</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-outside-interface/m-p/776067#M984516</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What do you mean by talk to each other. Do you mean from interface to interface. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you running multiple contexts. Do the contexts share a vlan on the outside interface. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please elaborate on what you need.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jul 2007 06:12:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-outside-interface/m-p/776067#M984516</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-07-12T06:12:16Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM outside interface</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-outside-interface/m-p/776068#M984517</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi jon,yes the fwsm is running multiple contexts.  in one of the contexts, i created multiple outside interfaces (e.g. vlan 500 and vlan 555).  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i also attached a diagram to have a clearer view&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jul 2007 06:27:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-outside-interface/m-p/776068#M984517</guid>
      <dc:creator>dennisopiso</dc:creator>
      <dc:date>2007-07-12T06:27:35Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM outside interface</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-outside-interface/m-p/776069#M984518</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;okay, so you have 2 interfaces on the outside within the same context. Are the client PC's in the same vlans as their relevant outside interface ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Presumably you are trying to get connectivity between your PC's ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you send a copy of your FWSM config ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jul 2007 06:31:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-outside-interface/m-p/776069#M984518</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-07-12T06:31:12Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM outside interface</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-outside-interface/m-p/776070#M984519</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;no, the client PCs are of different vlans with respect to their respective outside interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i dont have working config yet for this setup but here is my current config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nameif vlan325 internet security0&lt;/P&gt;&lt;P&gt;nameif vlan555 fwtest security0&lt;/P&gt;&lt;P&gt;nameif vlan327 inside security100&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit ip x.x.x.x [IP from inside] host y.y.y.y [PC1] &lt;/P&gt;&lt;P&gt;access-list internet_access_in extended permit ip host y.y.y.y [PC1] host x.x.x.x [IP from inside] &lt;/P&gt;&lt;P&gt;access-list fwtest_access_in extended permit ip any  &lt;/P&gt;&lt;P&gt;ip address inside &lt;/P&gt;&lt;P&gt;ip address internet &lt;/P&gt;&lt;P&gt;ip address fwtest &lt;/P&gt;&lt;P&gt;icmp permit any inside&lt;/P&gt;&lt;P&gt;icmp permit any internet&lt;/P&gt;&lt;P&gt;icmp permit any fwtest&lt;/P&gt;&lt;P&gt;no pdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (inside) 1 interface&lt;/P&gt;&lt;P&gt;global (internet) 1 interface&lt;/P&gt;&lt;P&gt;global (fwtest) 3 interface&lt;/P&gt;&lt;P&gt;global (bdoextranetout) 2 interface&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list inside_nat0_outbound&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;nat (internet) 1 access-list fwtest_nat0_outbound&lt;/P&gt;&lt;P&gt;nat (fwtest) 3 access-list bdoextranetin_pnat_outbound_V3&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface inside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface internet&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface fwtest&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jul 2007 06:52:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-outside-interface/m-p/776070#M984519</guid>
      <dc:creator>dennisopiso</dc:creator>
      <dc:date>2007-07-12T06:52:31Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM outside interface</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-outside-interface/m-p/776071#M984520</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Okay, before we do anything else can you add the following if it isn't already in your config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;/P&gt;&lt;P&gt;and let me know what happens.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jul 2007 06:59:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-outside-interface/m-p/776071#M984520</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-07-12T06:59:19Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM outside interface</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-outside-interface/m-p/776072#M984521</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;already added &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but still nothing happens&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jul 2007 07:03:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-outside-interface/m-p/776072#M984521</guid>
      <dc:creator>dennisopiso</dc:creator>
      <dc:date>2007-07-12T07:03:03Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM outside interface</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-outside-interface/m-p/776073#M984522</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;just thought i'd check &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You say the PC are not on the same vlans as the FWSM outside interfaces. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have Layer 3 SVI's for each outside interface of your FWSM on your switch ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It would help if you could send the full config for this context plus the relevant firewall lines (firewall vlan-group etc) from your switch plus an output of a sh ip int br on your switch. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jul 2007 07:18:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-outside-interface/m-p/776073#M984522</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-07-12T07:18:41Z</dc:date>
    </item>
  </channel>
</rss>

