Hi every one.in my network i have 6509 switch witch it is connected with access layer switches.connection between access layes switches and 6509 is trunk port.for all vlans,interfcae vlan in 6509 is shutdown and in FWSM all interface vlan X has ip address witch is default gateway of servers connected to access layer switches.my problem is that i want to inspect all vlans traffic before they goes to FWSM but i dont know how to monitor multiple vlans that they are recived via trunk port on 6509 and all vlan interfcaes has ip address only in the FWSM.???
You need to break your existing VLANs into two. Lets say existing vlans are 100 to 110. You need to make 10 new vlans, lets say 200 to 210. Then you need to bridge both of them on the IDSM. The 10X VLANs will remain on the access layer switches. However the FWSM SVIs will change from interface vlan 1xx to interface vlan 2xx. Allow 2xx VLANs on the FWSM trunk (Via the firewall-group command) and both the 1xx and 2xx commands on the IDSM trunk (Via the intrusion-detection command).