7-3
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 7 Configuring Interface Parameters
Configuring Interface Parameters
Default State of Interfaces
The default state of an interface depends on the type and the context mode.
In multiple context mode, all allocated interfaces are enabled by default, no matter what the state of the
interface is in the system execution space. However, for traffic to pass through the interface, the interface
also has to be enabled in the system execution space. If you shut down an interface in the system
execution space, then that interface is down in all contexts that share it.
In single mode or in the system execution space, interfaces have the following default states:
•
Physical interfaces—Disabled.
•
Redundant Interfaces—Enabled. However, for traffic to pass through the redundant interface, the
member physical interfaces must also be enabled.
•
Subinterfaces—Enabled. However, for traffic to pass through the subinterface, the physical interface
must also be enabled.
Default Security Level
The default security level is 0. If you name an interface “inside” and you do not set the security level
explicitly, then the security appliance sets the security level to 100.
Note
If you change the security level of an interface, and you do not want to wait for existing connections to
time out before the new security information is used, you can clear the connections using the
clear local-host
command.
Multiple Context Mode Guidelines
For multiple context mode, follow these guidelines:
•
Configure the context interfaces from within each context.
•
Configure context interfaces that you already assigned to the context in the system configuration.
Other interfaces are not available.
•
Configure Ethernet settings, redundant interfaces, and subinterfaces in the system configuration. No
other configuration is available. The exception is for failover interfaces, which are configured in the
system configuration. Do not configure failover interfaces with the procedures in this chapter. See
Chapter 14, “Configuring Failover,”
for more information.
Configuring the Interface
To configure an interface or subinterface, perform the following steps:
Step 1
To specify the interface you want to configure, enter the following command:
hostname(config)#
interface
{{
redundant
number
|
physical_interface
}[
.
subinterface
] |
mapped_name
}
hostname(config-if)#
The
redundant
number
argument is the redundant interface ID, such as
redundant 1
.
Append the
subinterface
ID to the physical or redundant interface ID separated by a period (.).
Summary of Contents for 500 Series
Page 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Page 45: ...P A R T 1 Getting Started and General Information ...
Page 46: ......
Page 277: ...P A R T 2 Configuring the Firewall ...
Page 278: ......
Page 561: ...P A R T 3 Configuring VPN ...
Page 562: ......
Page 891: ...P A R T 4 System Administration ...
Page 892: ......
Page 975: ...P A R T 5 Reference ...
Page 976: ......