5-3
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 5 Configuring Ethernet Settings, Redundant Interfaces, and Subinterfaces
Configuring and Enabling Fiber Interfaces
For the ASA 5500 series adaptive security appliance, enter the type followed by
slot
/
port
, for example,
gigabitethernet0/1
. Interfaces that are built into the chassis are assigned to slot 0, while interfaces on
the 4GE SSM are assigned to slot 1. The ASA 5550 adaptive security appliance has two banks of ports;
the bank on the left is slot 1 and the bank on the right is slot 0.
The ASA 5500 management interface is a Fast Ethernet interface designed for management traffic only,
and is specified as
management0/0
. You can, however, use it for through traffic if desired (see the
management-only
command). In transparent firewall mode, you can use the management interface (for
management purposes) in addition to the two interfaces allowed for through traffic. You can also add
subinterfaces to the management interface to provide management in each security context for multiple
context mode.
Step 2
(Optional) To set the speed, enter the following command:
hostname(config-if)#
speed
{
auto
|
10
|
100
|
1000
|
nonegotiate
}
The
auto
setting is the default. The
speed
nonegotiate
command disables link negotiation.
Step 3
(Optional) To set the duplex, enter the following command:
hostname(config-if)#
duplex
{
auto
|
full
|
half
}
The
auto
setting is the default.
Step 4
To enable the interface, enter the following command:
hostname(config-if)#
no shutdown
To disable the interface, enter the
shutdown
command. If you enter the
shutdown
command, you also
shut down all subinterfaces. If you shut down an interface in the system execution space, then that
interface is shut down in all contexts that share it.
Configuring and Enabling Fiber Interfaces
This section describes how to configure Ethernet settings for physical interfaces, and how to enable the
interface. By default, the connectors used on the 4GE SSM or for built-in interfaces in slot 1 on the ASA
5550 adaptive security appliance are the RJ-45 connectors. To use the fiber SFP connectors, you must
set the media type to SFP. The fiber interface has a fixed speed and does not support duplex, but you can
set the interface to negotiate link parameters (the default) or not to negotiate.
This section includes the following topics:
•
Default State of Physical Interfaces, page 5-3
•
Configuring the Fiber Interface, page 5-4
Default State of Physical Interfaces
By default, all physical interfaces are shut down. You must enable the physical interface before any
traffic can pass through it (either alone or as part of a redundant interface pair), or through a subinterface.
For multiple context mode, if you allocate an interface (physical, redundant, or subinterface) to a
context, the interfaces are enabled by default in the context. However, before traffic can pass through the
context interface, you must first enable the physical interface in the system configuration according to
this procedure.
Содержание 500 Series
Страница 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Страница 45: ...P A R T 1 Getting Started and General Information ...
Страница 46: ......
Страница 277: ...P A R T 2 Configuring the Firewall ...
Страница 278: ......
Страница 354: ...17 38 Cisco Security Appliance Command Line Configuration Guide OL 12172 03 Chapter 17 Configuring NAT NAT Examples ...
Страница 561: ...P A R T 3 Configuring VPN ...
Страница 562: ......
Страница 891: ...P A R T 4 System Administration ...
Страница 892: ......
Страница 975: ...P A R T 5 Reference ...
Страница 976: ......