Mac Address Lookups - Cisco FirePOWER ASA 5500 series Configuration Manual

Security appliance command line
Hide thumbs Also See for FirePOWER ASA 5500 series:
Table of Contents

Advertisement

Chapter 15
Firewall Mode Overview

MAC Address Lookups

When the security appliance runs in transparent mode, the outgoing interface of a packet is determined
by performing a MAC address lookup instead of a route lookup. Route statements can still be configured,
but they only apply to security appliance-originated traffic. For example, if your syslog server is located
on a remote network, you must use a static route so the security appliance can reach that subnet.
Using the Transparent Firewall in Your Network
Figure 15-7
subnet as the inside devices. The inside router and hosts appear to be directly connected to the outside
router.
Figure 15-7
Transparent Firewall Guidelines
Follow these guidelines when planning your transparent firewall network:
OL-10088-01
shows a typical transparent firewall network where the outside devices are on the same
Transparent Firewall Network
Internet
10.1.1.1
Network A
10.1.1.3
192.168.1.2
Network B
A management IP address is required; for multiple context mode, an IP address is required for each
context.
Unlike routed mode, which requires an IP address for each interface, a transparent firewall has an
IP address assigned to the entire device. The security appliance uses this IP address as the source
address for packets originating on the security appliance, such as system messages or AAA
communications.
Management IP
10.1.1.2
Cisco Security Appliance Command Line Configuration Guide
Transparent Mode Overview
15-9

Advertisement

Table of Contents
loading

This manual is also suitable for:

Pix 500 seriesCisco asa 5500 series

Table of Contents