Configuring PVLAN
The FWSM should have a 3.x code version or the preceding code, and the switch should have 12.2.18 SXFx version or the preceding code. Figure 23-10 shows the configuration of FWSM with PVLANs.
Figure 23-10 Configuration of FWSM with PVLANs
Figure 23-10 Configuration of FWSM with PVLANs

- Isolated VLAN 12 Community VLAN 13 Community VLAN 13
• VLAN 10 is the outside interface of the FWSM.
• VLAN 11 is the inside VLAN for the FWSM. It is also the primary VLAN (also referred as promiscuous VLAN) for the PVLAN in the PFC.
The sequence of configuring the PVLAN is important:
Step 1 Configure the primary PVLAN:
vlan 11
private-vlan primary 6504-E-1# show vlan private-vlan
Primary Secondary Type Ports
11 primary
Step 2 Configure the secondary VLANs:
vlan 12
private-vlan isolated
vlan 13
private-vlan community
vlan 14
private-vlan community
Step 3 Associate the secondary VLAN with the primary VLAN:
vlan 11
private-vlan primary private-vlan association 12-14
To verify the association with the primary VLAN, enter the show vlan private-vlan command:
6504-E-1# show vlan private-vlan
Primary Secondary Type Ports
11 12 isolated
11 13 community
11 14 community
Step 4 Configure the SVI for the primary VLAN 11:
interface Vlan11 ip address 10.2.1.1 255.255.255.0 private-vlan mapping 12-14
To verify the Layer 3 mapping, enter the show interface vlan 11 private-vlan mapping command:
6504-E-1# show interface vlan 11 private-vlan mapping
Interface Secondary VLANs vlanll 12, 13, 14
Step 5 Configure host ports in the switch:
— CLI for host port configuration:
switchport private-vlan host-association primary VLAN Secondary VLAN switchport mode private-vlan host
For example:
6504-E-l# show run interface g1/1
Building configuration... Current configuration : 218 bytes !
interface GigabitEthernet1/1 description connection to cat6k2 switchport switchport trunk encapsulation dot1q switchport private-vlan host-association 11 12 switchport mode private-vlan host no ip address end
To verify the switch port configuration, enter the show interface g 1/1 switchport command:
6504-E-1# show interface g 1/1 switchport
Name: Gi1/1 Switchport: Enabled
Administrative Mode: private-vlan host Operational Mode: private-vlan host Administrative Trunking Encapsulation: dot1q Operational Trunking Encapsulation: native Negotiation of Trunking: Off Access Mode VLAN: 1 (default) Trunking Native Mode VLAN: 1 (default) Voice VLAN: none
Administrative private-vlan host-association: 11 (VLAN0011) 12 (VLAN0012)
Administrative private-vlan mapping: none Administrative private-vlan trunk native VLAN: none Administrative private-vlan trunk encapsulation: dot1q Administrative private-vlan trunk normal VLANs: none Administrative private-vlan trunk private VLANs: none Operational private-vlan: none
Trunking VLANs Enabled: ALL Pruning VLANs Enabled: 2-1001 Capture Mode Disabled Capture VLANs Allowed: ALL Unknown unicast blocked: disabled Unknown multicast blocked: disabled
— CLI for promiscuous VLAN port configuration:
switchport private-vlan mapping primary-VLAN Secondary-VLAN switchport mode private-vlan promiscuous
For example:
6504-E-l# show run interface g1/2
Building configuration... Current configuration : 218 bytes interface GigabitEthernet1/2 switchport switchport private-vlan mapping 11 13-14 switchport mode private-vlan promiscuous no ip address media-type rj45 end
To verify the switch port configuration, enter the show interface g 1/2 switchport command:
6504-E-1# show interface g 1/2 switchport
Name: Gi1/2 Switchport: Enabled
Administrative Mode: private-vlan promiscuous Operational Mode: private-vlan promiscuous Administrative Trunking Encapsulation: negotiate Operational Trunking Encapsulation: native Negotiation of Trunking: Off Access Mode VLAN: 1 (default) Trunking Native Mode VLAN: 1 (default) Voice VLAN: none
Administrative private-vlan host-association: none Administrative private-vlan mapping: 11 (VLAN0011) 13 (VLAN0013) 14 (VLAN0014)
Administrative private-vlan trunk native VLAN: none Administrative private-vlan trunk encapsulation: dot1q Administrative private-vlan trunk normal VLANs: none Administrative private-vlan trunk private VLANs: none Operational private-vlan: none Trunking VLANs Enabled: ALL Pruning VLANs Enabled: 2-1001
Capture Mode Disabled Capture VLANs Allowed: ALL Unknown unicast blocked: disabled Unknown multicast blocked: disabled
Follow the steps to complete the PFC configuration:
Step 1 Follow the sequential steps to configure the PVLAN.
Step 2 Configure VLAN 10.
Step 3 Configure static routes.
Step 4 Configure the firewall VLAN group and the multiple interfaces command.
Example 23-11 shows FWSM configuration for Figure 23-10. Example 23-11 FWSM Configuration
FWSM-A# show run : Saved
hostname FWSM-A
enable password 8Ry2YjIyt7RRXU24 encrypted names !
interface Vlan10 nameif outside security-level 0
ip address 10.1.1.2 255.255.255.0
interface Vlan11 nameif inside security-level 100 ip address 10.2.1.2 255.255.255.0
passwd 2KFQnbNIdI.2KYOU encrypted ftp mode passive same-security-traffic permit intra-interface access-list 100 extended permit ip any any access-list 100 remark this is for the outside access-list 101 extended permit ip any any access-list 101 remark this is for the inside pager lines 24
logging console debugging logging monitor debugging mtu outside 1500
mtu inside 1500
no failover icmp permit any outside icmp permit any inside
Example 23-11 FWSM Configuration (Continued)
no asdm history enable arp timeout 14400
static (inside,outside) 10.2.100.1 10.2.100.1 netmask 255.255.255.255
static (inside,outside) 10.2.1.1 10.2.1.1 netmask 255.255.255.255
access-group 101 in interface outside access-group 100 out interface outside access-group 101 in interface inside access-group 101 out interface inside route outside 0.0.0.0 0.0.0.0 10.1.1.1 1
route inside 10.2.100.0 255.255.255.0 10.2.1.1 1
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02 timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 timeout mgcp-pat 0:05:00 sip 0:30:00 sip_media 0:02:00 timeout uauth 0:05:00 absolute no snmp-server location no snmp-server contact snmp-server enable traps snmp authentication linkup linkdown coldstart telnet timeout 5 ssh timeout 5
console timeout 0 !
class-map inspection_default match default-inspection-traffic
policy-map global_policy class inspection_default inspect dns maximum-length 512 inspect ftp inspect h323 h225 inspect h323 ras inspect netbios inspect rsh inspect skinny inspect smtp inspect sqlnet inspect sunrpc inspect tftp inspect sip inspect xdmcp
service-policy global_policy global prompt hostname context
Cryptochecksum:48794c0a97cda389441255764d5901b9 : end
Use the following command to verify PVLAN association with the primary VLAN in the FWSM:
FWSM-A# show np 1 vlan 14 I in private Vlan primary Vlan for private Vlan : 11
FWSM-A# show np 1 vlan 12 I in private Vlan primary Vlan for private Vlan : 11
FWSM-A# show np 1 vlan 13 I in private Vlan primary Vlan for private Vlan : 11
Even though there is no configuration in the FWSM with the code supporting PVLAN feature, when VLAN 11 (primary VLAN) is enabled in the FWSM, the NP 1 (Network Processor) of the FWSM picks up all the PVLANs from the PFC.
Continue reading here: Using the PISA for Enhanced Traffic Detection
Was this article helpful?