FWSM inter-context traffic

Unanswered Question
Feb 23rd, 2009

Hi,

I have 2 context's who are sharing vlan on a outside interface. They have ip's in a same subnet. Inside interfaces are in different vlan's. I have trouble with inter context traffic and by that i mean that i cann't establish traffic between context.

Networks on a inside interfaces have fine connectivity to public networks, but not to each other.

From one context i cann ping public IP of other, but not from inside.

Help please.

Danijel

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Jon Marshall Fri, 02/27/2009 - 07:20

The vlan that is shared on the outside of the contexts - is there a L3 SVI on the MSFC for this vlan.

So traffic from the inside of one context needs to go out through the outside interface, to the L3 vlan interface on the MSFC and then be routed back to outside interface of the other context. So does your MSFC know how to get to each inside subnet ?

Jon

dcerovecki Fri, 02/27/2009 - 07:29

Thank you for the reply I have solved the problem.

I have multiple context sharing outside vlan and in case of inter context traffic (if I'm right) Classiffier sends packet directly to other context and ignors static routes. Actually he prefers static translations over static routes.

I have tested that because i have a need for a Lawful Intercept on a MSFC but in a case of inter context traffic with shared outside interface i don't see it.

Thanks.

Actions

This Discussion