
5-11
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Chapter 5 Configuring the Firewall Mode
Transparent Mode Overview
•
For multiple context mode, each context must use different interfaces; you cannot share an interface
across contexts. The only exception to this is for an optional management VLAN, which can be
shared across multiple contexts.
•
For multiple context mode, each context typically uses different subnets. You can use overlapping
subnets, but your network topology requires router and NAT configuration to make it possible from
a routing standpoint.
•
You must use an extended access list to allow Layer 3 traffic, such as IP traffic, through the FWSM.
You can also optionally use an EtherType access list to allow non-IP traffic through.
Unsupported Features in Transparent Mode
Table 5-1
lists features that are not supported in transparent mode.
Table 5-1
Unsupported Features in Transparent Mode
Unsupported Feature
Description
DHCP relay
The transparent firewall can act as a DHCP server, but it does
not support the DHCP relay commands. DHCP relay is not
required because you can allow DHCP traffic to pass through
using an extended access list.
Dynamic routing protocols
You can, however, add static routes for traffic originating on
the FWSM. You can also allow dynamic routing protocols
through the FWSM using an extended access list.
IPv6 for the bridge group IP address or
management interface IP address
You can, however, pass the IPv6 EtherType using an
EtherType access list.
LoopGuard on the switch
Do not enable LoopGuard globally on the switch if the
FWSM is in transparent mode. LoopGuard is automatically
applied to the internal EtherChannel between the switch and
the FWSM, so after a failover and a failback, LoopGuard
causes the secondary unit to be disconnected because the
EtherChannel goes into the err-disable state.
Multicast
You can, however, allow multicast traffic through the FWSM
by allowing it in an extended access list.
Remote access VPN for management
You can use site-to-site VPN for management.
Содержание 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion
Страница 35: ...P A R T 1 Getting Started and General Information ...
Страница 36: ......
Страница 297: ...P A R T 2 Configuring the Security Policy ...
Страница 298: ......
Страница 521: ...P A R T 3 System Administration ...
Страница 522: ......
Страница 613: ...P A R T 4 Reference ...
Страница 614: ......