Configuring PVLAN

The FWSM should have a 3.x code version or the preceding code, and the switch should have 12.2.18 SXFx version or the preceding code. Figure 23-10 shows the configuration of FWSM with PVLANs.

Figure 23-10 Configuration of FWSM with PVLANs

Figure 23-10 Configuration of FWSM with PVLANs

Isolated VLAN 12 Community VLAN 13 Community VLAN 13

• VLAN 10 is the outside interface of the FWSM.

• VLAN 11 is the inside VLAN for the FWSM. It is also the primary VLAN (also referred as promiscuous VLAN) for the PVLAN in the PFC.

The sequence of configuring the PVLAN is important:

Step 1 Configure the primary PVLAN:

vlan 11

private-vlan primary 6504-E-1# show vlan private-vlan

Primary Secondary Type Ports

11 primary

Step 2 Configure the secondary VLANs:

vlan 12

private-vlan isolated

vlan 13

private-vlan community

vlan 14

private-vlan community

Step 3 Associate the secondary VLAN with the primary VLAN:

vlan 11

private-vlan primary private-vlan association 12-14

To verify the association with the primary VLAN, enter the show vlan private-vlan command:

6504-E-1# show vlan private-vlan

Primary Secondary Type Ports

11 12 isolated

11 13 community

11 14 community

Step 4 Configure the SVI for the primary VLAN 11:

interface Vlan11 ip address 10.2.1.1 255.255.255.0 private-vlan mapping 12-14

To verify the Layer 3 mapping, enter the show interface vlan 11 private-vlan mapping command:

6504-E-1# show interface vlan 11 private-vlan mapping

Interface Secondary VLANs vlanll 12, 13, 14

Step 5 Configure host ports in the switch:

— CLI for host port configuration:

switchport private-vlan host-association primary VLAN Secondary VLAN switchport mode private-vlan host

For example:

6504-E-l# show run interface g1/1

Building configuration... Current configuration : 218 bytes !

interface GigabitEthernet1/1 description connection to cat6k2 switchport switchport trunk encapsulation dot1q switchport private-vlan host-association 11 12 switchport mode private-vlan host no ip address end

To verify the switch port configuration, enter the show interface g 1/1 switchport command:

6504-E-1# show interface g 1/1 switchport

Name: Gi1/1 Switchport: Enabled

Administrative Mode: private-vlan host Operational Mode: private-vlan host Administrative Trunking Encapsulation: dot1q Operational Trunking Encapsulation: native Negotiation of Trunking: Off Access Mode VLAN: 1 (default) Trunking Native Mode VLAN: 1 (default) Voice VLAN: none

Administrative private-vlan host-association: 11 (VLAN0011) 12 (VLAN0012)

Administrative private-vlan mapping: none Administrative private-vlan trunk native VLAN: none Administrative private-vlan trunk encapsulation: dot1q Administrative private-vlan trunk normal VLANs: none Administrative private-vlan trunk private VLANs: none Operational private-vlan: none

Trunking VLANs Enabled: ALL Pruning VLANs Enabled: 2-1001 Capture Mode Disabled Capture VLANs Allowed: ALL Unknown unicast blocked: disabled Unknown multicast blocked: disabled

— CLI for promiscuous VLAN port configuration:

switchport private-vlan mapping primary-VLAN Secondary-VLAN switchport mode private-vlan promiscuous

For example:

6504-E-l# show run interface g1/2

Building configuration... Current configuration : 218 bytes interface GigabitEthernet1/2 switchport switchport private-vlan mapping 11 13-14 switchport mode private-vlan promiscuous no ip address media-type rj45 end

To verify the switch port configuration, enter the show interface g 1/2 switchport command:

6504-E-1# show interface g 1/2 switchport

Name: Gi1/2 Switchport: Enabled

Administrative Mode: private-vlan promiscuous Operational Mode: private-vlan promiscuous Administrative Trunking Encapsulation: negotiate Operational Trunking Encapsulation: native Negotiation of Trunking: Off Access Mode VLAN: 1 (default) Trunking Native Mode VLAN: 1 (default) Voice VLAN: none

Administrative private-vlan host-association: none Administrative private-vlan mapping: 11 (VLAN0011) 13 (VLAN0013) 14 (VLAN0014)

Administrative private-vlan trunk native VLAN: none Administrative private-vlan trunk encapsulation: dot1q Administrative private-vlan trunk normal VLANs: none Administrative private-vlan trunk private VLANs: none Operational private-vlan: none Trunking VLANs Enabled: ALL Pruning VLANs Enabled: 2-1001

Capture Mode Disabled Capture VLANs Allowed: ALL Unknown unicast blocked: disabled Unknown multicast blocked: disabled

Follow the steps to complete the PFC configuration:

Step 1 Follow the sequential steps to configure the PVLAN.

Step 2 Configure VLAN 10.

Step 3 Configure static routes.

Step 4 Configure the firewall VLAN group and the multiple interfaces command.

Example 23-11 shows FWSM configuration for Figure 23-10. Example 23-11 FWSM Configuration

FWSM-A# show run : Saved

hostname FWSM-A

enable password 8Ry2YjIyt7RRXU24 encrypted names !

interface Vlan10 nameif outside security-level 0

ip address 10.1.1.2 255.255.255.0

interface Vlan11 nameif inside security-level 100 ip address 10.2.1.2 255.255.255.0

passwd 2KFQnbNIdI.2KYOU encrypted ftp mode passive same-security-traffic permit intra-interface access-list 100 extended permit ip any any access-list 100 remark this is for the outside access-list 101 extended permit ip any any access-list 101 remark this is for the inside pager lines 24

logging console debugging logging monitor debugging mtu outside 1500

mtu inside 1500

no failover icmp permit any outside icmp permit any inside

Example 23-11 FWSM Configuration (Continued)

no asdm history enable arp timeout 14400

static (inside,outside) 10.2.100.1 10.2.100.1 netmask 255.255.255.255

static (inside,outside) 10.2.1.1 10.2.1.1 netmask 255.255.255.255

access-group 101 in interface outside access-group 100 out interface outside access-group 101 in interface inside access-group 101 out interface inside route outside 0.0.0.0 0.0.0.0 10.1.1.1 1

route inside 10.2.100.0 255.255.255.0 10.2.1.1 1

timeout xlate 3:00:00

timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02 timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 timeout mgcp-pat 0:05:00 sip 0:30:00 sip_media 0:02:00 timeout uauth 0:05:00 absolute no snmp-server location no snmp-server contact snmp-server enable traps snmp authentication linkup linkdown coldstart telnet timeout 5 ssh timeout 5

console timeout 0 !

class-map inspection_default match default-inspection-traffic

policy-map global_policy class inspection_default inspect dns maximum-length 512 inspect ftp inspect h323 h225 inspect h323 ras inspect netbios inspect rsh inspect skinny inspect smtp inspect sqlnet inspect sunrpc inspect tftp inspect sip inspect xdmcp

service-policy global_policy global prompt hostname context

Cryptochecksum:48794c0a97cda389441255764d5901b9 : end

Use the following command to verify PVLAN association with the primary VLAN in the FWSM:

FWSM-A# show np 1 vlan 14 I in private Vlan primary Vlan for private Vlan : 11

FWSM-A# show np 1 vlan 12 I in private Vlan primary Vlan for private Vlan : 11

FWSM-A# show np 1 vlan 13 I in private Vlan primary Vlan for private Vlan : 11

Even though there is no configuration in the FWSM with the code supporting PVLAN feature, when VLAN 11 (primary VLAN) is enabled in the FWSM, the NP 1 (Network Processor) of the FWSM picks up all the PVLANs from the PFC.

Continue reading here: Using the PISA for Enhanced Traffic Detection

Was this article helpful?

0 0