Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

IOS command for FWSM

I am running a 6509 w/Native IOS 12.1(19)E1. There is a command "firewall (multiple-vlan-interfaces)". I can not find any information on this command. I suspect that it has to do with Vlan interfaces on the MSFC connecting to the FWSM. Does anyone know what it's for or can direct me to information on this command.

2 REPLIES

Re: IOS command for FWSM

Hi,

This is a new command that was recently added to Cat6K code to allow multiple SVI's for VLAN's associated with a FWSM. In the past, you were restricted to having one SVI per all VLAN's associated with the FWSM. This was done primarily to prevent you from shooting yourself in the foot and allowing traffic to bypass the FWSM by routing it directly between SVI interfaces on the MSFC. In most cases, this command is not necessary and if you do enable it, you will need to configure policy routing to make sure traffic does not bypass the FWSM. Hereis a link to the release notes that discuss this new command (briefly). Hope this helps.

http://www.cisco.com/univercd/cc/td/doc/product/lan/cat6000/relnotes/ol_3549.htm#113025

Scott

New Member

Re: IOS command for FWSM

Thanks for the information. You confirmed what I suspected.

92
Views
0
Helpful
2
Replies