Routed Firewall and Transparent Firewall Modes
Routed Firewall Mode
• FWSM is considered to be a router hop in the network.
• It performs NAT between connected networks.
• OSPF or passive RIP (in single context mode).
• Supports up to 256 interfaces per context, with a maximum of 1000 interfaces across all contexts.
Transparent Firewall Mode
• FWSM acts like a "bump in the wire" and is not a router hop.
• The FWSM connects the same network on its inside and outside ports, but each port must be on a different VLAN.
• No dynamic routing protocols or NAT.
• Transparent mode only supports two interfaces per context.
© 2005 Cisco Systems, Ii
A FWSM can be configured to operate in transparent or routed mode. In routed mode, the FWSM is considered to be a router hop in the network. It performs NAT between connected networks, and can use OSPF or passive RIP in single-context mode. Routed mode supports up to 256 interfaces per context, with a maximum of 1000 interfaces across all contexts.
In transparent mode, the FWSM is not a router hop. The FWSM connects the same network on its inside and outside ports, but each port must be on a different VLAN. No dynamic routing protocols or NAT are required. Transparent mode only supports two interfaces, an inside interface and an outside interface.
You might use a transparent firewall to simplify your network configuration. Transparent mode is also useful if you want the firewall to be invisible to attackers. You can also use a transparent firewall for traffic that would otherwise be blocked in routed mode. For example, a transparent firewall can allow multicast streams.
You can partition a single FWSM into multiple virtual firewalls, known as security contexts.
Each context is an independent system, with its own security policy, interfaces, and administrators.
Multiple contexts are equivalent to having multiple stand-alone firewalls.
© 2005 Cisco Systems, Ii
You can partition a single FWSM into multiple virtual firewalls, known as security contexts. Each context is an independent system, with its own security policy, interfaces, and administrators. Multiple contexts are equivalent to having multiple stand-alone firewalls.
If desired, you can allow individual context administrators to implement the security policy on the context. The overall system administrator controls some of the resources so that one context cannot affect other contexts inadvertently, such as VLANs and system resources.
You can add and manage contexts by configuring them in the system configuration, which identifies basic settings for the card. The system administrator has privileges to manage all contexts. The system configuration does not include any network interfaces or network settings for itself; rather, when the system needs to access network resources (such as downloading the contexts from the server), it uses one of the contexts that is designated as the Admin context.
The Admin context is just like any other context, except that when a user logs into the Admin context (for example, over an SSH connection), that user has system administrator rights, and can access the system configuration and all other context configurations. Typically, the Admin context provides network access to network-wide resources, such as a syslog server or context configuration server.
Note In the default FWSM license, you can configure up to two contexts. For more contexts, you must purchase a context upgrade license.
Continue reading here: MSFC placement
Was this article helpful?
Readers' Questions
-
rorimac2 months ago
- Reply