cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
265
Views
0
Helpful
1
Replies

FWSM question on design

bbravo
Level 1
Level 1

Thanks everyone, I have dual 6509's with dual FWSM's, basically I need to be able to create FW rules to permit/deny traffic to/from user vlans to several server vlans and between other networks, etc. These VLANs are present in the 6509, can I do this by running transparent mode on the FWSM? First time setting up FWSM, any hints, recommendations are appreciated.

Thanks again.

1 Reply 1

hoffa2000
Level 3
Level 3

I assume you have the network set up as I had, the 6509 acting as a L3 switch between the different VLANs and their subnets.

What you can do in this case is to remove all SVIs you want to firewall from the 6509 and add them to the FWSM instead. If you then give the same IP to the FWSM interfaces as you had on the 6509 SVIs, and leave all rules wide open, you should have the same functionality as you had with the 6509 doing the routing.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card