cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
547
Views
0
Helpful
3
Replies

IDSM-2 before FWSM in 6509 switch

blackhat2020
Level 1
Level 1

Hi every one.in my network i have 6509 switch witch it is connected with access layer switches.connection between access layes switches and 6509 is trunk port.for all vlans,interfcae vlan in 6509 is shutdown and in FWSM all interface vlan X has ip address witch is default gateway of servers connected to access layer switches.my problem is that i want to inspect all vlans traffic before they goes to FWSM but i dont know how to monitor multiple vlans that they are recived via trunk port on 6509 and all vlan interfcaes has ip address only in the FWSM.???

1 Accepted Solution

Accepted Solutions

Farrukh Haroon
VIP Alumni
VIP Alumni

You need to break your existing VLANs into two. Lets say existing vlans are 100 to 110. You need to make 10 new vlans, lets say 200 to 210. Then you need to bridge both of them on the IDSM. The 10X VLANs will remain on the access layer switches. However the FWSM SVIs will change from interface vlan 1xx to interface vlan 2xx. Allow 2xx VLANs on the FWSM trunk (Via the firewall-group command) and both the 1xx and 2xx commands on the IDSM trunk (Via the intrusion-detection command).

Regards

Farrukh

View solution in original post

3 Replies 3

mchin345
Level 6
Level 6

Packets will flow normally through the system and into the service module. The service module will act normally upon the packets according to its application, such as firewall, NAM, IDS, and others. However, if a packet is forwarded out of the service module onto a VLAN with packet re-circulation, it may be dropped without reaching its next destination module

The same holds true for packets generated by the service module for management or monitoring traffic, such as SNMP traps, IDS alarms, and others. Any such traffic which is generated by the service module and transmitted out onto a VLAN with packet re-circulation may be dropped.

For further information click this link.

http://www.cisco.com/en/US/ts/fn/610/fn61935.html

Farrukh Haroon
VIP Alumni
VIP Alumni

You need to break your existing VLANs into two. Lets say existing vlans are 100 to 110. You need to make 10 new vlans, lets say 200 to 210. Then you need to bridge both of them on the IDSM. The 10X VLANs will remain on the access layer switches. However the FWSM SVIs will change from interface vlan 1xx to interface vlan 2xx. Allow 2xx VLANs on the FWSM trunk (Via the firewall-group command) and both the 1xx and 2xx commands on the IDSM trunk (Via the intrusion-detection command).

Regards

Farrukh

Hi,

Just to add something..Hope that the IP addresses of the FWSM SVIs to remain the same eventhough now they are residing in a differant VLAN.

Review Cisco Networking for a $25 gift card