EasyManua.ls Logo

Cisco Secure Firewall 3100 User Manual

Cisco Secure Firewall 3100
66 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #3 background image
traffic must exit the chassis on one interface and return on another interface to reach another instance.
You can add VLAN subinterfaces to a data interface to provide separate failover links per High Availability
pair.
Data-sharing—Use for regular data. These data interfaces can be shared by one or more instances. Each
instance can communicate over the backplane with all other instances that share this interface. Shared
interfaces can affect the number of instances you can deploy. Shared interfaces are not supported for
bridge group member interfaces (in transparent mode or routed mode), inline sets, passive interfaces, or
failover links.
Chassis Interfaces vs. Instance Interfaces
At the chassis level, you manage the basic Ethernet settings of physical interfaces, VLAN subinterfaces for
instances, and EtherChannel interfaces. Within the instance, you configure higher level settings. For example,
you can only create EtherChannels in the chassis; but you can assign an IP address to the EtherChannel within
the instance.
The following sections describe the interaction between the chassis and the instance for interfaces.
VLAN Subinterfaces
You can create VLAN subinterfaces within the instance, just as you would for any device.
You can also create VLAN subinterfaces in the chassis. The instance-defined subinterfaces are not subject to
the chassis limit. Choosing in which location to create subinterfaces depends on your network deployment
and personal preference. For example, to share a subinterface, you must create the subinterface on the chassis.
Another scenario that favors chassis subinterfaces comprises allocating separate subinterface groups on a
single interface to multiple instances. For example, you want to use Port-channel1 with VLAN 2–11 on
instance A, VLAN 12–21 on instance B, and VLAN 22–31 on instance C. If you create these subinterfaces
in the instance, then you would have to share the parent interface in the chassis, which may not be desirable.
See the following illustration that shows the three ways you can accomplish this scenario:
Multi-Instance Mode for the Secure Firewall 3100
3
Multi-Instance Mode for the Secure Firewall 3100
Chassis Interfaces vs. Instance Interfaces
Question and Answer IconNeed help?

Do you have a question about the Cisco Secure Firewall 3100 and is the answer not in the manual?

Cisco Secure Firewall 3100 Specifications

General IconGeneral
BrandCisco
ModelSecure Firewall 3100
CategoryServer
LanguageEnglish

Summary

About Multi-Instance Mode

Multi-Instance Mode vs. Appliance Mode

Compares multi-instance and appliance deployment modes for the Secure Firewall 3100.

Chassis Management Interface

Details the dedicated Management interface for chassis management in multi-instance mode.

Chassis Interfaces vs. Instance Interfaces

Explains the management of physical, VLAN, and EtherChannel interfaces at chassis and instance levels.

Shared Interface Scalability

Discusses conserving physical interface usage and supporting flexible deployments through interface sharing.

Packet Classification and Interface Types

How the Chassis Classifies Packets

Explains packet classification methods using unique interfaces and MAC addresses for instance routing.

Classification Examples

Illustrates packet classification scenarios for shared interfaces and incoming traffic from inside networks.

Transparent Firewall Instances

Covers unique interface requirements and packet classification for transparent firewall instances.

Inline Sets

Details interface requirements for inline sets and packet classification based on the ingress interface.

Cascading Instances

Defines cascading instances, where one instance is placed in front of another, and provides an example.

Typical Multi-Instance Deployment

Describes a common deployment scenario with three container instances in routed firewall mode.

Data-sharing Interfaces

Explains limits and best practices for data-sharing interfaces, including instances per shared interface.

Instance Configuration and Management

Automatic MAC Addresses for Instance Interfaces

Explains how the chassis automatically generates unique MAC addresses for instance interfaces.

Performance Scaling Factor for Multi-Instance Mode

Details how to calculate platform throughput based on assigned CPU cores for each instance.

Licenses for Instances

Clarifies that licenses are consumed per chassis, not per individual instance.

Requirements and Prerequisites for Instances

Lists necessary requirements and prerequisites for deploying instances, including model support and resources.

Guidelines and Limitations for Instances

Outlines general guidelines and specific limitations for multi-instance deployments, including unsupported features.

Configure Instances

Covers initial steps to configure instances, including enabling multi-instance mode via the console port.

Enable Multi-Instance Mode

Details the procedure to enable multi-instance mode using the FXOS CLI.

Add a Multi-Instance Chassis to the Management Center

Explains how to add the multi-instance chassis to the management center for unified management.

Configure Chassis Interfaces

Describes configuring basic Ethernet settings for physical and VLAN subinterfaces at the chassis level.

Configure an EtherChannel

Provides instructions for creating and configuring EtherChannel interfaces, including member selection and LACP settings.

Configure a Subinterface

Guides on adding subinterfaces to the chassis, including VLAN ID uniqueness rules and limits.

Add an Instance

Details the steps to add one or more container instances to the chassis via the management center.

Customize the System Configuration

Covers configuring chassis-level settings like SNMP and managing system configurations.

Configure SNMP

Explains how to configure SNMP settings for chassis system information access.

Import or Export the Chassis Configuration

Outlines the process for exporting and importing chassis configuration files for backup or migration.

Configure Chassis Platform Settings

Guides on creating and managing platform settings policies that can be applied across multiple chassis.

Configure DNS

Details how to configure DNS server settings for the chassis to resolve hostnames.

Configure SSH and SSH Access List

Covers enabling the SSH server and setting up access lists for secure remote management.

Configure Syslog

Explains how to enable and configure syslog logging for the chassis' FXOS operating system.

Configure Time Synchronization

Guides on setting up NTP servers for accurate time synchronization across the chassis.

Manage Multi-Instance Mode

Describes less common tasks related to managing multi-instance mode, including interface changes.

Change Interfaces Assigned to an Instance

Explains how to modify interface assignments for an existing instance and the impact of changes.

Change Chassis Management Settings at the FXOS CLI

Details how to modify management IP, gateway, and passwords using the FXOS CLI.

Monitoring and History

Monitoring Multi-Instance Mode

Provides FXOS commands to check the current mode and multi-instance setup details of the chassis.

Monitoring Instance Interfaces

Shows commands to monitor switch forwarding rules and ECMP/MCAST group membership for instances.

History for Multi-Instance Mode

Lists version history, new/modified screens, CLI commands, and platform restrictions for multi-instance mode.

Related product manuals