FWSM in transparent mode

Unanswered Question
Oct 11th, 2007
User Badges:

I want to put my FWSM in transparent mode. I have created the configuration on my 6500:


firewall multiple-vlan-interfaces

firewall module 6 vlan-group 1

firewall vlan-group 1 100,101

!

interface vlan 100

ip address 192.168.100.1 255.255.255.0

!


Config in my FWSM:


firewall transparent

nameif vlan100 outside security0

...

ip address 192.168.100.15 255.255.255.0

...

access-l acl_in permit ip any any

access-l acl_out permit ip any any

access-group acl_out in interface outside

access-group acl_in in interface inside


I want the IP trafic for all my end-stations to pass through my FWSM.


Thanks.





  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
amritpatek Wed, 10/17/2007 - 12:52
User Badges:
  • Silver, 250 points or more

Your configuration looks fine and you will be able to pass IP traffic through FWSM if your ACL are not blocking them explicitly. Also make sure you have mentioned all the vlans you want to monitor in your configuration.

Actions

This Discussion