FWSM - multiple interface and NAT

Answered Question

Hello:


I am in the process of configuring FWSM and want to have 3 inside interfaces and one outside. The Securty level for these interfaces as follows:

Outside - 0

Inside_1 - 80

Inside_2 - 70

Inside_3 - 60


But I don't want to perform NAT on any of them. Is this posiible (or do I have to setup same security levels for these interfaces to perform no NAT)?


Thanks in advance.........



Correct Answer by cisco24x7 about 9 years 3 months ago

With FWSM version 3.x or higher, the blade,

by default, will route traffics so you do

NOT have to do anything. You still need

ACL to go from low to high but NOT from high

to low.


If you still use fwsm version 2.x, you still

NEED to perform no NAT to go from high to

low


CCIE security

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (2 ratings)
Loading.
Correct Answer
cisco24x7 Mon, 02/11/2008 - 05:13
User Badges:
  • Silver, 250 points or more

With FWSM version 3.x or higher, the blade,

by default, will route traffics so you do

NOT have to do anything. You still need

ACL to go from low to high but NOT from high

to low.


If you still use fwsm version 2.x, you still

NEED to perform no NAT to go from high to

low


CCIE security

Actions

This Discussion