Configuring Security Contexts
This chapter describes how to configure multiple security contexts, and includes the following sections:
•
•
•
•
•
•
•
Security Context Overview
You can partition a single FWSM into multiple virtual devices, known as security contexts. Each context
has its own security policy, interfaces, and administrators. Multiple contexts are similar to having
multiple standalone devices. Many features are supported in multiple context mode, including routing
tables, firewall features, and management. Some features are not supported, including most dynamic
routing protocols.
This section provides an overview of security contexts, and includes the following topics:
•
•
•
•
•
•
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Security Context Overview, page 4-1
Enabling or Disabling Multiple Context Mode, page 4-10
Managing Memory for Rules, page 4-11
Configuring Resource Management, page 4-21
Configuring a Security Context, page 4-27
Changing Between Contexts and the System Execution Space, page 4-31
Managing Security Contexts, page 4-32
Common Uses for Security Contexts, page 4-2
Unsupported Features, page 4-2
Context Configuration Files, page 4-2
How the FWSM Classifies Packets, page 4-3
Sharing Interfaces Between Contexts, page 4-7
Management Access to Security Contexts, page 4-9
4
C H A P T E R
4-1