Network Device Virtualization
Several networking devices support virtualization. You can take advantage of device virtualization to segment and apply different policies within your infrastructure, while saving money in hardware. For example, you can partition a single hardware device into multiple virtual devices. In most cases, each virtual device acts as an independent device. The following devices support virtualization:
• Cisco Firewall Services Module (FWSM) for the Catalyst 6500 series switches
• Cisco IPS sensors running version 6.x or later
• The Cisco Application Control Engine (ACE) family for the Cisco Catalyst 6500 series switches
The Cisco PIX, Cisco ASA, and FWSM can be configured in multiple context mode in which each context has its own security policy, interfaces, and administrators. Having multiple contexts is similar to having multiple standalone devices. Figure 7-12 illustrates how a Cisco FWSM is deployed with three contexts (admin, context-1, and context-2) to segment different servers in a data center).
Figure 7-12 Security Contexts in FWSM
|
Admin Context |
Context-1 |
Context-2 |
|
(E-Commerce) |
(Database) |
|
Management Servers E-Commerce Servers Database Servers
Management Servers E-Commerce Servers Database Servers
Many features are supported in Cisco ASA, Cisco PIX, and Cisco FWSM running in multiple-context mode; however, some features are not supported, including VPN and dynamic routing protocols.
NOTE Chapter 10, "Data Center Security," includes sample configurations of Cisco FWSM virtualization to provide data center security. Chapter 12, "Case Studies," also has configuration examples of virtualization in Cisco PIX and Cisco ASA security appliances.
Continue reading here: Wireless Security
Was this article helpful?