cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
674
Views
0
Helpful
2
Replies

connecting a VRF mapped svi with a global SVI with FWSM

Gizmo37QC
Level 1
Level 1

Hi, with the help of a couple user here (thanks a lot again), we set up a FWSM in a 6513 chassis . we have set an admin context in routed mode and working. Now we have set a context in transparent mode.

Interface A is linked to a svi on the global router.

Interface B is linked to a svi mapped in a VRF

Before the assignement of vlan-group, svi A dont see svi B in the VRF.

Now The vlan are assigned and the bvi is set. there is a rule who permit icmp on both interface.

When we are in CLI in the context, we can ping SVI A at the global router. We can ping SVI B at the VRF.  The VRF can ping the bvi . The global router can ping the bvi also.

BUT, the VRF can NOT ping the global router nor the global router can ping the VRF svi and dont see anything in the log monitor.

We permit ip any any on both interface

We permit any ethertype rule also.

Is there something to do in the global router or the FWSM to allow these 2 SVI to exchange communication ?

Thanks !

1 Accepted Solution

Accepted Solutions

Giuseppe Larosa
Hall of Fame
Hall of Fame

Hello Gizmo,

happy to see that work is in progress

have you modified the MAC address used by one SVI so that they don't see to have the same MAC address?

other thought: you may need to permit ARP traffic that is not IP

>>

We permit ip any any on both interface

We permit any ethertype rule also.

well try the first trick

Edit:

have you assigned a security level to the two interfaces vlan on the transparent context?

set a different security level on the two.

Hope to help

Giuseppe

View solution in original post

2 Replies 2

Giuseppe Larosa
Hall of Fame
Hall of Fame

Hello Gizmo,

happy to see that work is in progress

have you modified the MAC address used by one SVI so that they don't see to have the same MAC address?

other thought: you may need to permit ARP traffic that is not IP

>>

We permit ip any any on both interface

We permit any ethertype rule also.

well try the first trick

Edit:

have you assigned a security level to the two interfaces vlan on the transparent context?

set a different security level on the two.

Hope to help

Giuseppe

yep, basic communication is working after i modify mac on the vrf-svi. Do you  know if there is any 'rule' for mac we can use when we do this ?  i only replace the first digit from 0 to 1 for now.

Next week we will go with more communication with servers and host, also exchange route between the vrf and the global router.

Thanks a lot again.

Review Cisco Networking products for a $25 gift card