
4-4
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Chapter 4 Configuring Security Contexts
Security Context Overview
static (inside,shared) 10.30.10.0 10.30.10.0 netmask 255.255.255.0
If you use dynamic NAT, an active NAT session is created when the real host creates a connection
through the shared interface. For traffic returning to the host, the active NAT session is used to classify
the packet.
To quickly identify possible overlaps between different contexts, a situation that leads to connectivity
problems, enter the
show np 3 static
command in the system execution space.
Note
For management traffic destined for an interface, the interface IP address is used for classification.
Invalid Classifier Criteria
The following configurations are not used for packet classification:
•
NAT exemption—The classifier does not use a NAT exemption configuration for classification
purposes because NAT exemption does not identify the mapped (shared) interface.
•
Routing table—The classifier does not use the routing table for classification. For example, if a
context includes a static route that points to an external router as the next-hop to a subnet, and a
different context includes a
static
command for the same subnet, then the classifier uses the
static
command to classify packets destined for that subnet and ignores the static route.
Summary of Contents for 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion
Page 35: ...P A R T 1 Getting Started and General Information ...
Page 36: ......
Page 297: ...P A R T 2 Configuring the Security Policy ...
Page 298: ......
Page 521: ...P A R T 3 System Administration ...
Page 522: ......
Page 613: ...P A R T 4 Reference ...
Page 614: ......