EasyManua.ls Logo

Cisco Secure Firewall 3100 User Manual

Cisco Secure Firewall 3100
66 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #5 background imageLoading...
Page #5 background image
Shared Interface Scalability
Instances can share data-sharing type interfaces. This capability lets you conserve physical interface usage as
well as support flexible networking deployments. When you share an interface, the chassis uses unique MAC
addresses to forward traffic to the correct instance. However, shared interfaces can cause the forwarding table
to grow large due to the need for a full mesh topology within the chassis (every instance must be able to
communicate with every other instance that is sharing the same interface). Therefore, there are limits to how
many interfaces you can share.
In addition to the forwarding table, the chassis maintains a VLAN group table for VLAN subinterface
forwarding. You can create up to 500 VLAN subinterfaces.
See the following limits for shared interface allocation:
Shared Interface Best Practices
For optimal scalability of the forwarding table, share as few interfaces as possible. Instead, you can create up
to 500 VLAN subinterfaces on one or more physical interfaces and then divide the VLANs among the container
instances.
When sharing interfaces, follow these practices in the order of most scalable to least scalable:
1. Best—Share subinterfaces under a single parent, and use the same set of subinterfaces with the same
group of instances.
For example, create a large EtherChannel to bundle all of your like-kind interfaces together, and then
share subinterfaces of that EtherChannel: Port-Channel1.2, 3, and 4 instead of Port-Channel2,
Multi-Instance Mode for the Secure Firewall 3100
5
Multi-Instance Mode for the Secure Firewall 3100
Shared Interface Scalability
Question and Answer IconNeed help?

Do you have a question about the Cisco Secure Firewall 3100 and is the answer not in the manual?

Cisco Secure Firewall 3100 Specifications

General IconGeneral
BrandCisco
ModelSecure Firewall 3100
CategoryServer
LanguageEnglish

Summary

About Multi-Instance Mode

Multi-Instance Mode vs. Appliance Mode

Compares multi-instance and appliance deployment modes for the Secure Firewall 3100.

Chassis Management Interface

Details the dedicated Management interface for chassis management in multi-instance mode.

Chassis Interfaces vs. Instance Interfaces

Explains the management of physical, VLAN, and EtherChannel interfaces at chassis and instance levels.

Shared Interface Scalability

Discusses conserving physical interface usage and supporting flexible deployments through interface sharing.

Packet Classification and Interface Types

How the Chassis Classifies Packets

Explains packet classification methods using unique interfaces and MAC addresses for instance routing.

Classification Examples

Illustrates packet classification scenarios for shared interfaces and incoming traffic from inside networks.

Transparent Firewall Instances

Covers unique interface requirements and packet classification for transparent firewall instances.

Inline Sets

Details interface requirements for inline sets and packet classification based on the ingress interface.

Cascading Instances

Defines cascading instances, where one instance is placed in front of another, and provides an example.

Typical Multi-Instance Deployment

Describes a common deployment scenario with three container instances in routed firewall mode.

Data-sharing Interfaces

Explains limits and best practices for data-sharing interfaces, including instances per shared interface.

Instance Configuration and Management

Automatic MAC Addresses for Instance Interfaces

Explains how the chassis automatically generates unique MAC addresses for instance interfaces.

Performance Scaling Factor for Multi-Instance Mode

Details how to calculate platform throughput based on assigned CPU cores for each instance.

Licenses for Instances

Clarifies that licenses are consumed per chassis, not per individual instance.

Requirements and Prerequisites for Instances

Lists necessary requirements and prerequisites for deploying instances, including model support and resources.

Guidelines and Limitations for Instances

Outlines general guidelines and specific limitations for multi-instance deployments, including unsupported features.

Configure Instances

Covers initial steps to configure instances, including enabling multi-instance mode via the console port.

Enable Multi-Instance Mode

Details the procedure to enable multi-instance mode using the FXOS CLI.

Add a Multi-Instance Chassis to the Management Center

Explains how to add the multi-instance chassis to the management center for unified management.

Configure Chassis Interfaces

Describes configuring basic Ethernet settings for physical and VLAN subinterfaces at the chassis level.

Configure an EtherChannel

Provides instructions for creating and configuring EtherChannel interfaces, including member selection and LACP settings.

Configure a Subinterface

Guides on adding subinterfaces to the chassis, including VLAN ID uniqueness rules and limits.

Add an Instance

Details the steps to add one or more container instances to the chassis via the management center.

Customize the System Configuration

Covers configuring chassis-level settings like SNMP and managing system configurations.

Configure SNMP

Explains how to configure SNMP settings for chassis system information access.

Import or Export the Chassis Configuration

Outlines the process for exporting and importing chassis configuration files for backup or migration.

Configure Chassis Platform Settings

Guides on creating and managing platform settings policies that can be applied across multiple chassis.

Configure DNS

Details how to configure DNS server settings for the chassis to resolve hostnames.

Configure SSH and SSH Access List

Covers enabling the SSH server and setting up access lists for secure remote management.

Configure Syslog

Explains how to enable and configure syslog logging for the chassis' FXOS operating system.

Configure Time Synchronization

Guides on setting up NTP servers for accurate time synchronization across the chassis.

Manage Multi-Instance Mode

Describes less common tasks related to managing multi-instance mode, including interface changes.

Change Interfaces Assigned to an Instance

Explains how to modify interface assignments for an existing instance and the impact of changes.

Change Chassis Management Settings at the FXOS CLI

Details how to modify management IP, gateway, and passwords using the FXOS CLI.

Monitoring and History

Monitoring Multi-Instance Mode

Provides FXOS commands to check the current mode and multi-instance setup details of the chassis.

Monitoring Instance Interfaces

Shows commands to monitor switch forwarding rules and ECMP/MCAST group membership for instances.

History for Multi-Instance Mode

Lists version history, new/modified screens, CLI commands, and platform restrictions for multi-instance mode.

Related product manuals