cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
833
Views
0
Helpful
2
Replies

Transparent Firewall

lm20ele
Level 1
Level 1

I have read the following definition a couple times:

Transparent mode, the FWSM acts like a "bump in the wire," or a "stealth firewall," and is not a router hop.

What I understand with the previous sentence is that: The FWSM connects the same network on its inside and outside interfaces, but each interface must be on a different VLAN.

However, are both vlans going to share same subnet???

2 Replies 2

rochopra
Cisco Employee
Cisco Employee

Transparent firewall will bridge between vlan and not route, so if you are using different subnets you will need layer 3 routing device to route packets between subnets.

~Rohit

Jon Marshall
Hall of Fame
Hall of Fame

Hi

In answer to your question yes you have 2 vlans but only one IP subnet. This setup is also used on other devices such as load balancers.

The reason you need to do this is to avoid a spanning-tree loop. Assuming you are running PVST+ then having 2 vlans but only one subnet allows you to bridge the subnet with the FWSM.

HTH

Jon

Review Cisco Networking products for a $25 gift card