Tuesday, June 05, 2012
Overview of the Firewall Services Module
Overview of the Firewall Services Module
The Cisco Firewall Services Module (FWSM) for Cisco Catalyst 6500 series switches is a dedicated firewall solution that builds upon Cisco ASA (Adaptive Security Algorithm)
stateful inspection technology. As already happened with the firewall functionality on
ASA appliances, the FWSM also has Cisco PIX Firewall as its main ancestor. One natural consequence of that influence is the similarity that can be readily detected on the
Command Line Interface (CLI) and configuration philosophy for all these three products.
The FWSM is a specialized, firewall-only device. It can be combined though with other
Catalyst 6500 services modules, such as the Application Control Engine (ACE) module,
which enables a single chassis to provide additional services such as Server Load
Balancing (SLB).
The communication between the FWSM and the underlying Catalyst 6500 happens
through the switch backplane. When using FWSM, any physical port on the switch can
be enabled for firewall policies, saving time and efforts related to cabling. On the other
hand, only those VLANs in the hosting chassis that have been explicitly assigned to the
module will have access to FWSM services. This means that the switch can keep behaving as usual for the remaining VLANs.
The FWSM is well suited for intranet Data Centers, where it can, for instance, control
client access to the server-side VLANs. It also fits well for virtualized deployments, such as segmenting departments inside a company or offering firewall to customers, as an optional infrastructure service, within a service provider environment. One distinctive
feature of the FWSM resides on its capability to run any combination of Transparent
mode and Routed mode security contexts.
■ NP3 is frequently referred to as the Session Manager. It processes the first packet in a
connection, counts established and incomplete connections, and creates translations.
It is also in charge of performing TCP sequence number randomization .
■ NP1 and NP2 are called the Fast Path. These processors, among other tasks, are
responsible for maintaining the connection table, performing per-packet session
lookup, translating addresses (Network Address Translation [NAT] and Port Address
Translation [PAT]), and reassembling fragments.
■ The Control Point (CP) corresponds to the main CPU: It handles traffic destined to or
sourced from the FWSM, which basically corresponds to management (SNMP, SSH,
Telnet, HTTPS, and so on) and control protocols (failover tasks, routing protocols,
TACACS+, and so on). The CP also takes care of application protocol inspection
(translating addresses embedded on the application layer, filtering application commands, and so on). The CP, the processor running the FWSM code, is often called the Slow Path.
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment