04-28-2005 07:16 PM - edited 03-09-2019 11:06 AM
Hi Sir,
I'm a newbie to FWSM. I'm going thru some configuration examples of FWSM in transparent, multiple security context mode.
Refer to the following example,
Let's look at CustomerA context. The "inside" is on VLAN 5 and "outside" is on VLAN 151. Being transparent mode, hosts on inside network can be on the same IP subnet as the MSFC and point their default gateway to MSFC. What confuses me is, to put protected hosts on this context, we will have to assign physical switchports to VLAN 5, but the MSFC is terminating it on VLAN 151 (interface Vlan151). Is it this complicate network operation and troubleshooting?
Please advise.
Thank you.
B.Rgds,
Lim TS
05-03-2005 05:51 AM
Hi Lim,
VLAN is used to isolate protected segment(VLAN5) and unprotected segment(VLAN151) although both segments are on the same IP subnet. Transparent firewall acts as a 'bridge' between 2 segment. This will ensure that traffic from protected segment goes through the firewall inspection before reaching unprotected segment and vice-versa.
05-03-2005 06:49 PM
Hi Yong,
Thanks for the info.
I understand that's how it works but it looked confusing to me at first because we assign VLAN 5 to switchports (for protected host connections) but MSFC is terminating it on interface Vlan151. It looks a bit confusing from network operation & troubleshooting standpoint.
Thank you.
B.Rgds,
Lim TS
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide