Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Shared Firewall config

Requirement: Multiple small vlans behind a single shared firewall.

Current proposed setup: Pix or Nokia FW-1 firewall connected on the outside interface to Internet Backbone providers, inside Lan interface connected to 2948 switch to provide multiple vlan's to groups of web servers. It is esential that the hosts on the vlan's are not able to see any other host on another vlan. The firewall is running NAT.

Problem: It is not possible to setup truncking between the 2948 and firewall (required to enable the correct use of vlan's.

Possible solution(?): A 2621 router is placed between the firewall and switch to enable the switch to use truncking. Problems with NAT and ARP between the firewall and vlan hosts.

Is there anyone who has managed a similar setup?

  • Other Security Subjects
New Member

Re: Shared Firewall config

Pix only support Ethernet II (DIX) encapsulation.

No trunking protocol are supported.


New Member

Re: Shared Firewall config


You can use a pix firewall(525 or 535) with more than 2 interfaces .The number of ethernet interfaces should be equal to the number of vlans (theres a limit though to the number of ethernet cards a pix 515,525,535 can support)and and routes ,nats ,static and global commands in the firewall.

Hope the above thing makes some sense??