Cisco PIX 525 Dokumentacja Strona 197

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj
Przeglądanie stron 196
12-11
Cisco Security Appliance Command Line Configuration Guide
OL-6721-01
Chapter 12 Firewall Mode Overview
Transparent Mode Overview
Each directly connected network must be on the same subnet.
Do not specify the security appliance management IP address as the default gateway for connected
devices; devices need to specify the router on the other side of the security appliance as the default
gateway.
For multiple context mode, each context must use different interfaces; you cannot share an interface
across contexts.
For multiple context mode, each context typically uses a different subnet. You can use overlapping
subnets, but your network topology requires router and NAT configuration to make it possible from
a routing standpoint.
You must use an extended access list to allow Layer 3 traffic, such as IP traffic, through the security
appliance.
You can also optionally use an EtherType access list to allow non-IP traffic through.
Unsupported Features in Transparent Mode
The following features are not supported in transparent mode:
NAT
NAT is performed on the upstream router.
Dynamic routing protocols
You can, however, add static routes for traffic originating on the security appliance. You can also
allow dynamic routing protocols through the security appliance using an extended access list.
IPv6
DHCP relay
The transparent firewall can act as a DHCP server, but it does not support the DHCP relay
commands. DHCP relay is not required because you can allow DHCP traffic to pass through using
an extended access list.
Quality of Service
Multicast
You can, however, allow multicast traffic through the security appliance by allowing it in an
extended access list.
VPN termination for through traffic
The transparent firewall supports site-to-site VPN tunnels for management connections only. It does
not terminate VPN connections for traffic through the security appliance. You can pass VPN traffic
through the security appliance using an extended access list, but it does not terminate
non-management connections.
Przeglądanie stron 196
1 2 ... 192 193 194 195 196 197 198 199 200 201 202 ... 603 604

Komentarze do niniejszej Instrukcji

Brak uwag