data:image/s3,"s3://crabby-images/7a462/7a462b1b637bec8eb235a7103bd1931719ab4791" alt="Cisco 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion Configuration Manual Download Page 646"
B-22
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Appendix B Sample Configurations
Failover Example Configurations
route outside 0 0 209.165.201.5 1
telnet 10.0.1.65 255.255.255.255 inside
access-list INTERNET extended permit ip any any
access-group INTERNET in interface inside
! Allows all inside hosts to access the outside for any IP traffic
Secondary FWSM System Configuration (Example 6)
You do not need to configure any contexts, just the following minimal configuration for the system.
You must first enable multiple context mode using the
mode multiple
command. Then enter the
activation key to allow more than two contexts using the
activation-key
command. The mode and the
activation key are not stored in the configuration file, even though they do endure reboots. If you view
the configuration on the FWSM using the
write terminal
,
show startup
, or
show running
commands,
the mode displays after the FWSM Release line (blank means single mode, “<system>” means you are
in multiple mode in the system configuration, and <context> means you are in multiple mode in a
context).
failover lan interface faillink vlan 10
failover interface ip faillink 192.168.253.1 255.255.255.252 standby 192.168.253.2
failover lan unit secondary
failover
Switch Configuration (Example 6)
The following lines in the Cisco IOS switch configuration on both switches relate to the FWSM. For
information about configuring redundancy for the switch, see the switch documentation.
...
firewall module 1 vlan-group 1
firewall vlan-group 1 10,11,200-203
interface vlan 200
ip address 209.165.201.1 255.255.255.224
standby 200 ip 209.165.201.5
standby 200 priority 110
standby 200 preempt
standby 200 timers 5 15
standby 200 authentication Secret
no shutdown
interface range gigabitethernet 2/1-3
channel-group 2 mode on
switchport trunk encapsulation dot1q
no shutdown
...
Example 7: Transparent Mode Failover
The following configuration shows a multiple context mode FWSM with transparent mode contexts in
one switch, and another FWSM in a second switch acting as a backup (see
Figure B-6
). Each context (A,
B, and C) monitors the inside interface and outside interface.
The secondary FWSM is also in multiple context mode, and has the same software release.
Summary of Contents for 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion
Page 35: ...P A R T 1 Getting Started and General Information ...
Page 36: ......
Page 297: ...P A R T 2 Configuring the Security Policy ...
Page 298: ......
Page 521: ...P A R T 3 System Administration ...
Page 522: ......
Page 613: ...P A R T 4 Reference ...
Page 614: ......