Cisco PIX 525 Dokumentacja Strona 50

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj
Przeglądanie stron 49
3-6
Cisco Security Appliance Command Line Configuration Guide
OL-6721-01
Chapter 3 Enabling Multiple Context Mode
Security Context Overview
For transparent firewalls, you must use unique interfaces. For the classifier, the lack of NAT support in
transparent mode leaves unique interfaces as the only means of classification. Figure 3-3 shows a host
on the Context B inside network accessing the Internet. The classifier assigns the packet to Context B
because the ingress interface is Gigabit Ethernet 1/0.3, which is assigned to Context B.
Figure 3-3 Transparent Firewall Contexts
Sharing Interfaces Between Contexts
Routed Mode Only
The security appliance lets you share an interface between contexts. For example, you might share the
outside interface to conserve interfaces. You can also share inside interfaces to share resources between
contexts.
This section includes the following topics:
Shared Interface Guidelines, page 3-7
Cascading Security Contexts, page 3-9
Host
10.1.3.13
Host
10.1.2.13
Host
10.1.1.13
Context A Context B
GE 1/0.3GE 1/0.2
Admin
Context
GE 1/0.1
GE 0/0.3GE 0/0.1
GE 0/0.2
Classifier
Inside
Customer A
Inside
Customer B
Internet
Admin
Network
92401
Przeglądanie stron 49
1 2 ... 45 46 47 48 49 50 51 52 53 54 55 ... 603 604

Komentarze do niniejszej Instrukcji

Brak uwag