During the attempt to configure multiple switched virtual interfaces (SVIs), this produces a command-line interface (CLI) error message as shown in this example:
Forcing SVI 7 to stay shutdown (SVI 551 tied to line card in slot 1.)
For security reasons, by default, only one SVI can exist between the Multilayer Switch Feature Card (MSFC) and the Firewall Service Module (FWSM). For example, if you misconfigure the system with multiple SVIs, you can accidentally allow traffic to pass around the FWSM if you assign both the inside and outside VLANs to the MSFC.
Note: In order to prevent traffic from bypassing the firewall, policy-routing can be required when you enable support for multiple VLAN interfaces on the switch.
In order to enable support for multiple SVIs on your switch, use one of these commands.
Similarly, in CatOS, issue the set firewall multiple-vlan-interfaces enable command.
Also, while you configure your switch for the FWSM VLANs and receive an error message that indicatesthat you have more than one SVI, look at your switch and/or MSFC configuration in order to ensure that only one Layer 3 interface or VLAN interface exists as part of the firewall VLANs.
Hello, I have to change a Cisco 3845 and install a Cisco ISR 4451. The problem is I have a subinterface with 30 helper-address: When I insert more than 16 directions using helper-address command, I have an error message which says that the router does not...
I have some closet with relatively old 6509s that I am trying to configure for 802.1x and MAB. For my test case, I am using a Cisco AP which is getting profiled from ISE and added to the MAB group. ISE shows the authentication passing and return...
Hello Not a technical question, please remove if not allowed. Looking to purchase Cisco Switches and a router for home lab and Cisco Cert. Does anyone sell Cisco Retail? I have a local Micro Center in Maryland and Virginia with a lim...
Community,I am studying for the CCNP ROUTE exam and noticed something interesting in the routing table for one of the routers in my GNS3 Lab that I have never noticed before: When the router didnt have a locally connected 10.0.0.0/8 network it presen...