cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
831
Views
0
Helpful
2
Replies

Transparent Firewall

lm20ele
Level 1
Level 1

I have read the following definition a couple times:

Transparent mode, the FWSM acts like a "bump in the wire," or a "stealth firewall," and is not a router hop.

What I understand with the previous sentence is that: The FWSM connects the same network on its inside and outside interfaces, but each interface must be on a different VLAN.

However, are both vlans going to share same subnet???

2 Replies 2

rochopra
Cisco Employee
Cisco Employee

Transparent firewall will bridge between vlan and not route, so if you are using different subnets you will need layer 3 routing device to route packets between subnets.

~Rohit

Jon Marshall
Hall of Fame
Hall of Fame

Hi

In answer to your question yes you have 2 vlans but only one IP subnet. This setup is also used on other devices such as load balancers.

The reason you need to do this is to avoid a spanning-tree loop. Assuming you are running PVST+ then having 2 vlans but only one subnet allows you to bridge the subnet with the FWSM.

HTH

Jon

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card