Cisco PIX 525 Especificações Página 95

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir
  • Página
    / 466
  • Índice
  • MARCADORES
  • Avaliado. / 5. Com base em avaliações de clientes
Vista de página 94
2-35
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 2 Establishing Connectivity
Using VLANs with the Firewall
Note When configuring failover for a VLAN interface, hello packets are sent over the physical interface, so
the physical interface must be configured with an ip address.
Using Logical Interfaces
With Version 6.3, you can assign VLANs to physical interfaces on the PIX Firewall, or you can configure
multiple logical interfaces on a single physical interface and assign each logical interface to a specific
VLAN.
A logical interface is similar in many respects to a so-called physical interface. Both logical and physical
interfaces are software objects (the actual physical object is the network interface card on the
PIX
Firewall unit). What is called the physical interface for the purpose of configuration is a software
object that has both Layer 2 (Data link) and Layer 3 (Network) attributes. Layer 2 attributes include
maximum transmission unit (MTU) size and failover status, while Layer 3 attributes include IP address
and security level.
A logical interface has only Layer 3 attributes. As a result, you can issue certain commands, such as
failover link if_name or failover lan interface if_name on a physical interface that you cannot use with
a logical interface. When you disable a physical interface, all the associated logical interfaces are also
disabled. When you disable a logical interface, it only affects the logical interface.
Note Failover is supported with VLAN interfaces. But the failover lan interface command does not support
VLAN interfaces or the failover link commands.
The number of logical interfaces that you can configure varies according to the model. The minimum
number of interfaces for any PIX
Firewall is two. Table 2-6 lists the maximum number of logical
interfaces supported on a specific PIX Firewall model:
Ta b l e 2-6 Maximum Number of Interfaces Supported on PIX Firewall Models
Model Restricted License
1. PIX 501 and PIX 506/506E do not support Restricted/Unrestricted licenses.
1
PIX 501
2. One interface of the PIX 501 connects to an integrated 4-port switch.
2
NA NA NA 2 2 Not
supported
PIX 506/506E NA NA NA 4 2 2
PIX 515/515E 5 3 3 10 6 8
PIX 520
3. PIX 520 supports a connection license and the number of interfaces does not vary with the connection license.
3
NA NA NA 12 6 10
PIX 525 8 6 6 12 8 10
PIX 535 10 8 8 24 10 22
Unrestricted License
Total
Interfaces
Physical
Interfaces
Logical
Interfaces
Total
Interfaces
Physical
Interfaces
Logical
Interfaces
Vista de página 94
1 2 ... 90 91 92 93 94 95 96 97 98 99 100 ... 465 466

Comentários a estes Manuais

Sem comentários