Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

FWSM - VLAN Groups

Is there any significance to the FW-VLAN-GROUP that is configured on the Switch other than mapping the group to a FWSM slot? Or in other words, can I apply policies to a FW-VLAN-GROUP on the FWSM?

The current environment has 50+ VLANS and all of the VLANS will need some sort of security. I would like to group the VLANS into more manageable FW-VLANS (zones) …and route using the MSFC between VLANS in the same FW-VLAN-GROUP. Then, use the FWSM to route between security zones. Can this be done?


Re: FWSM - VLAN Groups

Basically the "firewall vlan-group" command , along with the "firewall module" command, maps the VLAN's to the firewall module. Any other VLAN configured on the switch but not directly specified as belonging to the FWSM will be routed via the MSFC. I am however not sure if you can route the fw-vlans using the MSFC. You might find this configuration reference useful in case you haven't seen this earlier.