Contents
xi
Cisco Security Appliance Command Line Configuration Guide
OL-10088-01
Testing the Failover Functionality 14-46
Controlling and Monitoring Failover 14-46
Forcing Failover 14-46
Disabling Failover 14-47
Restoring a Failed Unit or Failover Group 14-47
Monitoring Failover 14-47
Failover System Messages 14-48
Debug Messages 14-48
SNMP 14-48
CHAPTER
15 Firewall Mode Overview 15-1
Routed Mode Overview 15-1
IP Routing Support 15-1
Network Address Translation 15-1
How Data Moves Through the Security Appliance in Routed Firewall Mode 15-2
An Inside User Visits a Web Server 15-3
An Outside User Visits a Web Server on the DMZ 15-4
An Inside User Visits a Web Server on the DMZ 15-5
An Outside User Attempts to Access an Inside Host 15-6
A DMZ User Attempts to Access an Inside Host 15-7
Transparent Mode Overview 15-7
Transparent Firewall Network 15-8
Allowing Layer 3 Traffic 15-8
Passing Traffic Not Allowed in Routed Mode 15-8
MAC Address Lookups 15-9
Using the Transparent Firewall in Your Network 15-9
Transparent Firewall Guidelines 15-9
Unsupported Features in Transparent Mode 15-10
How Data Moves Through the Transparent Firewall 15-11
An Inside User Visits a Web Server 15-12
An Outside User Visits a Web Server on the Inside Network 15-13
An Outside User Attempts to Access an Inside Host 15-14
CHAPTER
16 Identifying Traffic with Access Lists 16-1
Access List Overview 16-1
Access List Types 16-2
Access Control Entry Order 16-2
Access Control Implicit Deny 16-3
IP Addresses Used for Access Lists When You Use NAT 16-3