02-01-2010 09:25 AM - edited 03-11-2019 10:03 AM
hi! We've a fwsm module in our core sw and i'm new to this. just want to find out what's the purpose of the bridge-group 1 command on the inside and outside interfaces? + what's the BVI1 for? is it related to the brige-group 1 command on the inside n outside command? can i have different bridge-group number for inside and outside? thx
interface Vlan100
nameif outside
bridge-group 1
security-level 0
interface BVI1
ip address 10.10.10.1 255.255.255.0
Solved! Go to Solution.
02-01-2010 09:31 AM
hi! We've a fwsm module in our core sw and i'm new to this. just want to find out what's the purpose of the bridge-group 1 command on the inside and outside interfaces? + what's the BVI1 for? is it related to the brige-group 1 command on the inside n outside command? can i have different bridge-group number for inside and outside? thx
interface Vlan100
nameif outside
bridge-group 1
security-level 0
interface BVI1
ip address 10.10.10.1 255.255.255.0
This configuration is for when you run the FWSM in transparent mode. With transparent mode the IP subnet is the same on the outside and the inside. You use 2 vlans, one for the outside and one for the inside but as i say they both use the same IP subnet.
You then join (ie. bridge) the 2 vlans together with the FWSM. So the bridge group needs to match so the FWSM knows which vlans to join together. The BVI is management IP for this transparent firewall.
Jon
02-01-2010 09:31 AM
hi! We've a fwsm module in our core sw and i'm new to this. just want to find out what's the purpose of the bridge-group 1 command on the inside and outside interfaces? + what's the BVI1 for? is it related to the brige-group 1 command on the inside n outside command? can i have different bridge-group number for inside and outside? thx
interface Vlan100
nameif outside
bridge-group 1
security-level 0
interface BVI1
ip address 10.10.10.1 255.255.255.0
This configuration is for when you run the FWSM in transparent mode. With transparent mode the IP subnet is the same on the outside and the inside. You use 2 vlans, one for the outside and one for the inside but as i say they both use the same IP subnet.
You then join (ie. bridge) the 2 vlans together with the FWSM. So the bridge group needs to match so the FWSM knows which vlans to join together. The BVI is management IP for this transparent firewall.
Jon
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: