Configuring a Transparent Firewall

Use the following steps to configure a firewall for transparent mode.

1. Enter transparent firewall mode:

Firewall(config)# firewall transparent

By default, a firewall operates in the routed mode. You can use this command to initiate the transparent firewall mode. Transparent mode begins immediately and does not require a firewall reload.

Because transparent and routed modes use different approaches to network security, the running configuration is cleared as soon as transparent mode begins. The idea is to enter transparent mode and build an appropriate configuration from scratch.

For that reason, you should save the routed mode running configuration to Flash memory or to an external server. That way, you have a copy in case you need to revert back to routed mode or you need to refer to some portion of that configuration.

You can always display the current firewall mode with the show firewall command. As an example, a firewall is configured for transparent mode in the following command sequence:

Firewall# show firewall Firewall mode: Router Firewall# configure terminal

Firewall(config)# firewall transparent Switched to transparent mode Firewall(config)# exit Firewall#

Firewall# show firewall Firewall mode: Transparent Firewall#

2. Configure an interface

In transparent mode, none of the firewall interfaces can support an IP address. You still have to configure the necessary interface media parameters (speed and duplex), any virtual LAN (VLAN) information, a logical name, and a security level. These parameters are configured in the following steps:

a. Define a physical interface.

0 0

Post a comment