EasyManua.ls Logo

Cisco Secure Firewall 3100 User Manual

Cisco Secure Firewall 3100
66 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #7 background imageLoading...
Page #7 background image
Figure 4: Fair: Shared Subinterfaces on Separate Parents
3. Worst—Share individual parent interfaces (physical or EtherChannel).
This method uses the most forwarding table entries.
Figure 5: Worst: Shared Parent Interfaces
How the Chassis Classifies Packets
Each packet that enters the chassis must be classified, so that the chassis can determine to which instance to
send a packet.
Unique Interfaces—If only one instance is associated with the ingress interface, the chassis classifies the
packet into that instance. For bridge group member interfaces (in transparent mode or routed mode),
inline sets, or passive interfaces, this method is used to classify packets at all times.
Unique MAC Addresses—The chassis automatically generates unique MAC addresses for all interfaces,
including shared interfaces. If multiple instances share an interface, then the classifier uses unique MAC
addresses assigned to the interface in each instance. An upstream router cannot route directly to an
instance without unique MAC addresses. You can also set the MAC addresses manually when you
configure each interface within the application.
If the destination MAC address is a multicast or broadcast MAC address, the packet is duplicated and delivered
to each instance.
Note
Multi-Instance Mode for the Secure Firewall 3100
7
Multi-Instance Mode for the Secure Firewall 3100
How the Chassis Classifies Packets
Question and Answer IconNeed help?

Do you have a question about the Cisco Secure Firewall 3100 and is the answer not in the manual?

Cisco Secure Firewall 3100 Specifications

General IconGeneral
BrandCisco
ModelSecure Firewall 3100
CategoryServer
LanguageEnglish

Summary

About Multi-Instance Mode

Multi-Instance Mode vs. Appliance Mode

Compares multi-instance and appliance deployment modes for the Secure Firewall 3100.

Chassis Management Interface

Details the dedicated Management interface for chassis management in multi-instance mode.

Chassis Interfaces vs. Instance Interfaces

Explains the management of physical, VLAN, and EtherChannel interfaces at chassis and instance levels.

Shared Interface Scalability

Discusses conserving physical interface usage and supporting flexible deployments through interface sharing.

Packet Classification and Interface Types

How the Chassis Classifies Packets

Explains packet classification methods using unique interfaces and MAC addresses for instance routing.

Classification Examples

Illustrates packet classification scenarios for shared interfaces and incoming traffic from inside networks.

Transparent Firewall Instances

Covers unique interface requirements and packet classification for transparent firewall instances.

Inline Sets

Details interface requirements for inline sets and packet classification based on the ingress interface.

Cascading Instances

Defines cascading instances, where one instance is placed in front of another, and provides an example.

Typical Multi-Instance Deployment

Describes a common deployment scenario with three container instances in routed firewall mode.

Data-sharing Interfaces

Explains limits and best practices for data-sharing interfaces, including instances per shared interface.

Instance Configuration and Management

Automatic MAC Addresses for Instance Interfaces

Explains how the chassis automatically generates unique MAC addresses for instance interfaces.

Performance Scaling Factor for Multi-Instance Mode

Details how to calculate platform throughput based on assigned CPU cores for each instance.

Licenses for Instances

Clarifies that licenses are consumed per chassis, not per individual instance.

Requirements and Prerequisites for Instances

Lists necessary requirements and prerequisites for deploying instances, including model support and resources.

Guidelines and Limitations for Instances

Outlines general guidelines and specific limitations for multi-instance deployments, including unsupported features.

Configure Instances

Covers initial steps to configure instances, including enabling multi-instance mode via the console port.

Enable Multi-Instance Mode

Details the procedure to enable multi-instance mode using the FXOS CLI.

Add a Multi-Instance Chassis to the Management Center

Explains how to add the multi-instance chassis to the management center for unified management.

Configure Chassis Interfaces

Describes configuring basic Ethernet settings for physical and VLAN subinterfaces at the chassis level.

Configure an EtherChannel

Provides instructions for creating and configuring EtherChannel interfaces, including member selection and LACP settings.

Configure a Subinterface

Guides on adding subinterfaces to the chassis, including VLAN ID uniqueness rules and limits.

Add an Instance

Details the steps to add one or more container instances to the chassis via the management center.

Customize the System Configuration

Covers configuring chassis-level settings like SNMP and managing system configurations.

Configure SNMP

Explains how to configure SNMP settings for chassis system information access.

Import or Export the Chassis Configuration

Outlines the process for exporting and importing chassis configuration files for backup or migration.

Configure Chassis Platform Settings

Guides on creating and managing platform settings policies that can be applied across multiple chassis.

Configure DNS

Details how to configure DNS server settings for the chassis to resolve hostnames.

Configure SSH and SSH Access List

Covers enabling the SSH server and setting up access lists for secure remote management.

Configure Syslog

Explains how to enable and configure syslog logging for the chassis' FXOS operating system.

Configure Time Synchronization

Guides on setting up NTP servers for accurate time synchronization across the chassis.

Manage Multi-Instance Mode

Describes less common tasks related to managing multi-instance mode, including interface changes.

Change Interfaces Assigned to an Instance

Explains how to modify interface assignments for an existing instance and the impact of changes.

Change Chassis Management Settings at the FXOS CLI

Details how to modify management IP, gateway, and passwords using the FXOS CLI.

Monitoring and History

Monitoring Multi-Instance Mode

Provides FXOS commands to check the current mode and multi-instance setup details of the chassis.

Monitoring Instance Interfaces

Shows commands to monitor switch forwarding rules and ECMP/MCAST group membership for instances.

History for Multi-Instance Mode

Lists version history, new/modified screens, CLI commands, and platform restrictions for multi-instance mode.

Related product manuals