EasyManua.ls Logo

Cisco Secure Firewall 3100 User Manual

Cisco Secure Firewall 3100
66 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
Page #1 background imageLoading...
Page #1 background image
Multi-Instance Mode for the Secure Firewall
3100
You can deploy the Secure Firewall 3100 as a single device (appliance mode) or as multiple container instances
(multi-instance mode). This chapter describes how to deploy the device in multi-instance mode.
About Multi-Instance Mode, on page 1
Licenses for Instances, on page 14
Requirements and Prerequisites for Instances, on page 14
Guidelines and Limitations for Instances, on page 16
Configure Instances, on page 18
Monitoring Multi-Instance Mode, on page 62
History for Multi-Instance Mode, on page 65
About Multi-Instance Mode
In multi-instance mode, you can deploy multiple container instances on a single chassis that act as completely
independent devices.
Multi-Instance Mode vs. Appliance Mode
You can run the device in either multi-instance mode or appliance mode.
Appliance Mode
Appliance mode is the default. The device runs the native threat defense image and acts as a single device.
The only chassis-level configuration available (on the Chassis Manager page) is for network module
management (breakout ports or enabling/disabling a network module).
Multi-Instance Mode
If you change to multi-instance mode, the device runs the Secure Firewall eXtensible Operating System
(FXOS) on the chassis, while each instance runs separate threat defense images. You can configure the mode
using the FXOS CLI.
Because multiple instances run on the same chassis, you need to perform chassis-level management of:
CPU and memory resources using resource profiles.
Multi-Instance Mode for the Secure Firewall 3100
1
Question and Answer IconNeed help?

Do you have a question about the Cisco Secure Firewall 3100 and is the answer not in the manual?

Cisco Secure Firewall 3100 Specifications

General IconGeneral
BrandCisco
ModelSecure Firewall 3100
CategoryServer
LanguageEnglish

Summary

About Multi-Instance Mode

Multi-Instance Mode vs. Appliance Mode

Compares multi-instance and appliance deployment modes for the Secure Firewall 3100.

Chassis Management Interface

Details the dedicated Management interface for chassis management in multi-instance mode.

Chassis Interfaces vs. Instance Interfaces

Explains the management of physical, VLAN, and EtherChannel interfaces at chassis and instance levels.

Shared Interface Scalability

Discusses conserving physical interface usage and supporting flexible deployments through interface sharing.

Packet Classification and Interface Types

How the Chassis Classifies Packets

Explains packet classification methods using unique interfaces and MAC addresses for instance routing.

Classification Examples

Illustrates packet classification scenarios for shared interfaces and incoming traffic from inside networks.

Transparent Firewall Instances

Covers unique interface requirements and packet classification for transparent firewall instances.

Inline Sets

Details interface requirements for inline sets and packet classification based on the ingress interface.

Cascading Instances

Defines cascading instances, where one instance is placed in front of another, and provides an example.

Typical Multi-Instance Deployment

Describes a common deployment scenario with three container instances in routed firewall mode.

Data-sharing Interfaces

Explains limits and best practices for data-sharing interfaces, including instances per shared interface.

Instance Configuration and Management

Automatic MAC Addresses for Instance Interfaces

Explains how the chassis automatically generates unique MAC addresses for instance interfaces.

Performance Scaling Factor for Multi-Instance Mode

Details how to calculate platform throughput based on assigned CPU cores for each instance.

Licenses for Instances

Clarifies that licenses are consumed per chassis, not per individual instance.

Requirements and Prerequisites for Instances

Lists necessary requirements and prerequisites for deploying instances, including model support and resources.

Guidelines and Limitations for Instances

Outlines general guidelines and specific limitations for multi-instance deployments, including unsupported features.

Configure Instances

Covers initial steps to configure instances, including enabling multi-instance mode via the console port.

Enable Multi-Instance Mode

Details the procedure to enable multi-instance mode using the FXOS CLI.

Add a Multi-Instance Chassis to the Management Center

Explains how to add the multi-instance chassis to the management center for unified management.

Configure Chassis Interfaces

Describes configuring basic Ethernet settings for physical and VLAN subinterfaces at the chassis level.

Configure an EtherChannel

Provides instructions for creating and configuring EtherChannel interfaces, including member selection and LACP settings.

Configure a Subinterface

Guides on adding subinterfaces to the chassis, including VLAN ID uniqueness rules and limits.

Add an Instance

Details the steps to add one or more container instances to the chassis via the management center.

Customize the System Configuration

Covers configuring chassis-level settings like SNMP and managing system configurations.

Configure SNMP

Explains how to configure SNMP settings for chassis system information access.

Import or Export the Chassis Configuration

Outlines the process for exporting and importing chassis configuration files for backup or migration.

Configure Chassis Platform Settings

Guides on creating and managing platform settings policies that can be applied across multiple chassis.

Configure DNS

Details how to configure DNS server settings for the chassis to resolve hostnames.

Configure SSH and SSH Access List

Covers enabling the SSH server and setting up access lists for secure remote management.

Configure Syslog

Explains how to enable and configure syslog logging for the chassis' FXOS operating system.

Configure Time Synchronization

Guides on setting up NTP servers for accurate time synchronization across the chassis.

Manage Multi-Instance Mode

Describes less common tasks related to managing multi-instance mode, including interface changes.

Change Interfaces Assigned to an Instance

Explains how to modify interface assignments for an existing instance and the impact of changes.

Change Chassis Management Settings at the FXOS CLI

Details how to modify management IP, gateway, and passwords using the FXOS CLI.

Monitoring and History

Monitoring Multi-Instance Mode

Provides FXOS commands to check the current mode and multi-instance setup details of the chassis.

Monitoring Instance Interfaces

Shows commands to monitor switch forwarding rules and ECMP/MCAST group membership for instances.

History for Multi-Instance Mode

Lists version history, new/modified screens, CLI commands, and platform restrictions for multi-instance mode.

Related product manuals