B-8
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Appendix B Sample Configurations
Example 3: Shared Resources for Multiple Contexts
!
System messages are sent to the syslog server on the DMZ network
logging host dmz 192.168.2.2
logging enable
Example 3: Shared Resources for Multiple Contexts
This configuration includes multiple contexts for multiple departments within a company. Each
department has its own security context so that each department can have its own security policy.
However, the syslog, mail, and AAA servers are shared across all departments. These servers are placed
on a shared interface (see
Figure B-3
).
Department 1 has a web server that outside users who are authenticated by the AAA server can access.
Figure B-3
Example 3
See the following sections for the configurations for this scenario:
•
Example 3: System Configuration, page B-9
•
Example 3: Admin Context Configuration, page B-9
Shared
Network
Admin
Context
Department 1
Department 2
Mail Server
10.1.1.7
Syslog Server
10.1.1.8
Inside
10.1.0.1
Inside
10.1.2.1
Shared
10.1.1.1
Shared
10.1.1.2
Shared
10.1.1.3
Outside
209.165.201.3
Outside
209.165.201.4
Outside
209.165.201.5
209.165.201.2
Inside
10.1.3.1
Admin Host
10.1.0.15
Internet
Inside
AAA Server
10.1.1.6
Web Server
10.1.2.3
Config Server
10.1.0.16
126980
Summary of Contents for 500 Series
Page 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Page 45: ...P A R T 1 Getting Started and General Information ...
Page 46: ......
Page 277: ...P A R T 2 Configuring the Firewall ...
Page 278: ......
Page 561: ...P A R T 3 Configuring VPN ...
Page 562: ......
Page 891: ...P A R T 4 System Administration ...
Page 892: ......
Page 975: ...P A R T 5 Reference ...
Page 976: ......