05-19-2009 02:07 AM - edited 03-04-2019 04:48 AM
Hi, I want to confirm on thing. Firewall module is mandatory to enable CBAC ?
05-19-2009 02:39 AM
Depends what you mean by "firewall module". On software based routers, you'll need an IOS that includes the firewall feature set. On somthing like the 6500, believe you'll need the FWSM (firewall service module - hardware).
05-19-2009 03:08 AM
It is fine with 6500 switch having fwsm module. What about 3600/2800 router where I have not purchased any Firewall module .. Can I configure CBAC ?
05-19-2009 03:23 AM
"What about 3600/2800 router where I have not purchased any Firewall module .. Can I configure CBAC ?"
If the IOS supports the firewall feature set (and CBAC), yes.
05-19-2009 04:18 AM
One more qn for Failover on 6500 FWSM module. Failover vlan should be created on local switch.
"failover lan interface FAILOVER vlan 995
failover link STATEFUL vlan 996".
I am not seeing any vlan 995/996 on local switch ?
05-19-2009 09:24 AM
Hello Rupesh,
these Vlans 995 and 996 need to exist only at layer2 on the chassis supervisor.
They are L2 trunked to the internal 6 GE etherchannel between chassis and FWSM.
you should use a dedicated physical GE link in vlan 995 between the two chassis
and another GE link for vlan 996 between the two chassis.
Avoid to have vlans 995 and 996 carried on the L2 generic trunk between chassis (that would be preferred by STP if it is 10GE or bundle of multiple GE) or modify STP costs for each vlan so that it is not preferred.
Hope to help
Giuseppe
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide