6509 w/ FWSM

Unanswered Question
May 24th, 2007

We just installed a 6509 with an FWSM and I need to setup SSH access to the 6509 for monitoring. I would like to have the switch accessible by an inside IP address. However, I have setup the MSFC on the outside of the FWSM so traffic is routed by the MSFC to the outside interface of the FWSM and then internally through three different internal vlans out the FWSM.

My question is, if I create an additional Interface VLAN on the 6509 with and internal IP address, will this bypass the FWSM? I've read that if you have two Layer3 VLAN interfaces, you could bypass the firewall, but if I do not include the vlan in the firewall vlan-group will it still bypass the FWSM?

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
jbrunner007 Thu, 05/24/2007 - 10:06

it will bypass the firewall in your configuration. if the vlans are in the firewall vlan-group however, I have never tried this. It will not bypass them if the svi's (int vlan xxx)

dont come up/up. I suspect they will.

-Joe

Actions

This Discussion