
4-7
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Chapter 4 Configuring Security Contexts
Security Context Overview
Figure 4-3
shows a transparent firewall with a host on the Context B inside network accessing the
Internet. The classifier assigns the packet to Context B because the ingress interface is VLAN 300,
which is assigned to Context B.
Figure 4-3
Transparent Firewall Contexts
Sharing Interfaces Between Contexts
The FWSM lets you share an interface between contexts. For transparent mode, you can only share a
management-only VLAN; all through-traffic interfaces must be unique. For management traffic destined
for an interface, the interface IP address is used for classification. For non-management-only VLANs in
routed mode, packet classification requirements might make sharing interfaces impractical. Because the
classifier relies on active NAT sessions to classify the destination addresses to a context, the classifier is
limited by how you can configure NAT. If you do not want to perform NAT, you must use unique
interfaces.
Host
10.1.3.13
Host
10.1.2.13
Host
10.1.1.13
Context A
Context B
VLAN 350
VLAN 250
Admin
Context
VLAN 150
VLAN 300
VLAN 100
VLAN 200
Classifier
Inside
Customer A
Inside
Customer B
Internet
Admin
Network
92401
FWSM
FWSM
FWSM
Summary of Contents for 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion
Page 35: ...P A R T 1 Getting Started and General Information ...
Page 36: ......
Page 297: ...P A R T 2 Configuring the Security Policy ...
Page 298: ......
Page 521: ...P A R T 3 System Administration ...
Page 522: ......
Page 613: ...P A R T 4 Reference ...
Page 614: ......