Enabling or Disabling Multiple Context Mode
•
As the system administrator, you can access all contexts.
When you change to a context from admin or the system, your username changes to the default
"enable_15" username. If you configured command authorization in that context, you need to either
configure authorization privileges for the "enable_15" user, or you can log in as a different name for
which you provide sufficient privileges in the command authorization configuration for the context. To
log in with a username, enter the login command.
For example, you log in to the admin context with the username "admin." The admin context does not
have any command authorization configuration, but all other contexts include command authorization.
For convenience, each context configuration includes a user "admin" with maximum privileges. When
you change from the admin context to context A, your username is altered, so you must log in again as
"admin" by entering the login command. When you change to context B, you must again enter the login
command to log in as "admin."
Context Administrator Access
You can access a context using Telnet, SSH, or ASDM. If you log in to a non-admin context, you can
only access the configuration for that context. You can provide individual logins to the context. See
Chapter 23, "Configuring Management Access,"
configure management authentication.
Enabling or Disabling Multiple Context Mode
Your FWSM might already be configured for multiple security contexts depending on how you ordered
it from Cisco. If you are upgrading, however, you might need to convert from single mode to multiple
mode by following the procedures in this section. ASDM does not support changing modes, so you need
to change modes using the CLI.
This section includes the following topics:
•
•
•
Backing Up the Single Mode Configuration
When you convert from single mode to multiple mode, the FWSM converts the running configuration
into two files. The original startup configuration is not saved, so if it differs from the running
configuration, you should back it up before proceeding.
Enabling Multiple Context Mode
The context mode (single or multiple) is not stored in the configuration file, even though it does endure
reboots. If you need to copy your configuration to another device, set the mode on the new device to
match using the mode command.
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
4-10
Access the admin context using Telnet, SSH, or ASDM. You can have a maximum of 15 SSH or
Telnet sessions in the admin context.
See
Chapter 23, "Configuring Management Access,"
Backing Up the Single Mode Configuration, page 4-10
Enabling Multiple Context Mode, page 4-10
Restoring Single Context Mode, page 4-11
Chapter 4
to enable Telnet, SSH, and SDM access.
to enable Telnet, SSH, and SDM access and to
Configuring Security Contexts
OL-20748-01