During the attempt to configure multiple switched virtual interfaces (SVIs), this produces a command-line interface (CLI) error message as shown in this example:
Forcing SVI 7 to stay shutdown (SVI 551 tied to line card in slot 1.)
For security reasons, by default, only one SVI can exist between the Multilayer Switch Feature Card (MSFC) and the Firewall Service Module (FWSM). For example, if you misconfigure the system with multiple SVIs, you can accidentally allow traffic to pass around the FWSM if you assign both the inside and outside VLANs to the MSFC.
Note: In order to prevent traffic from bypassing the firewall, policy-routing can be required when you enable support for multiple VLAN interfaces on the switch.
In order to enable support for multiple SVIs on your switch, use one of these commands.
Similarly, in CatOS, issue the set firewall multiple-vlan-interfaces enable command.
Also, while you configure your switch for the FWSM VLANs and receive an error message that indicatesthat you have more than one SVI, look at your switch and/or MSFC configuration in order to ensure that only one Layer 3 interface or VLAN interface exists as part of the firewall VLANs.
This is my first time ever posting in here so I apologize if this is not the right venue to ask this question. I have been working on my CCNP and then following on for a CCIE Enterprise Infrastructure. However, I noticed that there is no way to...
Is it possible to configure Ether-Channel on an ASA Firewall, and if so how? Also, is it worth it? Looking for Redundancy For example, having 2-3 Ethernet lines feeding a switch from the ASA. Thoughts on this?
Hi EveryOne, If a router goes active for a destination, and if before it receives all its replies it detectes a delay increase for the same network it goes active for, the router will wait to receive all its replies, and then check if the best receiv...
Hi all,can anyone point me in the right directionMy customer is asking for an ASR1001-X to create a pseudowire connetion on a mpls circuitThe Asr already has an advanced enterprise services licensemy question is do i need to supply any other licenses ...
Hi everyone, I've been scratching my head with this issue, thus reaching out for help. I have a 3560G running 2.2(58)SE2 and I want to configure dot1x. Here is the config: aaa new-modelaaa group server radius myradiusaaa g...