Lammle.com
  • Instructor-Led Training
    • Browse by Course
      • All Courses
      • CompTIA Courses
      • Cisco® Courses
      • Microsoft Courses
      • Wireless Courses
      • IT & Security Courses
      • Attend Online
    • Browse by Date
    • Browse by City
    • Deals and Discounts
      • Spring Specials
      • From CCENT to CCNA in 2 Weeks
      • From CCNA to CCNP in 3 Weeks
      • Corporate Solutions
      • Government Solutions
        • Government Solutions
        • GSA Pricing
      • Recent Newsletters
    • Corporate Solutions
    • Government Solutions
      • Government Solutions
      • GSA Pricing
    • Testimonials
    • Internetworking Salary Survey
  • Locations
    • Atlanta
    • Austin
    • Chicago
    • Dallas/Fort Worth
    • Denver
    • Durham
    • Glendale
    • Houston
    • Live Online Only
    • Los Angeles
    • New Hampshire
    • New York
    • Orlando
    • Raleigh
    • San Diego
    • San Francisco
    • Santa Rosa
    • Washington D.C.
    • England
    • Germany
    Locations
  • Self-Paced Learning
    • Online Live Training
    • E-Learning
    • Online CCNA Video Training
    • Practice Questions
    • DVD and Audio (Lammle Press)
    • Books
  • Blog
  • Forum
  • GlobalNet Consulting
    • Overview
    • Experience
    • Our Team
    • Methodology
    • Projects
    • Contact Us
  • About
    • About Todd Lammle
    • About GlobalNet Training & Consulting
      • About GlobalNet Consulting
    • Student Complaint Policy
    • Terms of Service
      • Privacy Policy
      • Why was my account disabled?
  • Contact
    • Feedback Form
    • Site Map
Home Forum

Official Lammle User Forum


Go Back   Lammle Forum > Cisco® CCSP > PIX and ASA
Reload this Page Multiple Context Mode
Register FAQ Members List Social Groups Calendar Search Today's Posts Mark Forums Read

Reply
 
Thread Tools Display Modes
  #1  
Old 12-12-2006, 08:15 PM
sproe
Guest
 
Posts: n/a
Default Multiple Context Mode

We were discussing multiple context mode in class today and it sounded like something I should do with my new ASA5520. But then tonight I read that some features are not available in multiple context mode, so that made me rethink the whole thing. It seems you lose VPN, Multicast & Dynamic Routing with multiple context mode. I know we want the VPN for sure and not sure I want to limit our abilities on the rest. Am I reading this right?

--Sandy
Reply With Quote
  #2  
Old 12-13-2006, 01:27 PM
aguilera aguilera is offline
 
Join Date: Aug 2006
Location: Dallas, Texas
Posts: 66
Send a message via AIM to aguilera Send a message via Skype™ to aguilera
Default

You are right!

Multiple context mode does not support :

•Dynamic routing protocols (only static routes)

•VPN (You can not use the FW as a VPN server or VPN Peer)
* If you choose to use Security Context, you can terminate the VPN connections on the Edge Router, or an a Concentrator.

•Multicast (a way around this is to create a tunnel for mcast traffic to flow though)
Reply With Quote
aguilera
View Public Profile
Send a private message to aguilera
Visit aguilera's homepage!
Find all posts by aguilera
  #3  
Old 08-13-2007, 07:13 AM
pixuser pixuser is offline
Junior Member
 
Join Date: Aug 2007
Posts: 1
Default Re: Multiple context mode

Could you elaborate on the case of virtual instances with VPN.

Don't you think that this would be a very important feature to be enabled on PIX ?

Thanks,
pixuser
Reply With Quote
pixuser
View Public Profile
Find all posts by pixuser
  #4  
Old 10-18-2007, 10:40 AM
aguilera aguilera is offline
 
Join Date: Aug 2006
Location: Dallas, Texas
Posts: 66
Send a message via AIM to aguilera Send a message via Skype™ to aguilera
Default Virtual Instances...

Virtual Private Networks? or Virtual Firewalls?

Remember... Routers and other VPN Gateways were terminating VPN connections way before PIX and ASAs were.

Unfortunately, integrated functionality has spoiled us. In some ways it has even skewed our perception of device functionality vs. a device's ability. In this case, using one function disables the firewalls ability to perform another.

Remember just because a box has the function available doesn't mean you have to use it. Evaluate your environment and see if you can justify the need for security contexts.

If your working environment has site-to-site VPNs or remote access VPNs and is solely dependent on your Firewall to act as a VPN Peer or VPN Server then using Security Contexts are not an option for you.

If your working environment has alternate VPN Gateways then Security Contexts could be an option for you.

If the loss of Dynamic Routing, VPNs and Multicasting are not issue for you then go for it.

- aguilera
Reply With Quote
aguilera
View Public Profile
Send a private message to aguilera
Visit aguilera's homepage!
Find all posts by aguilera
Reply

Bookmarks
  • Submit Thread to Digg Digg
  • Submit Thread to del.icio.us del.icio.us
  • Submit Thread to StumbleUpon StumbleUpon
  • Submit Thread to Google Google
Thread Tools
Show Printable Version Show Printable Version
Email this Page Email this Page
Display Modes
Linear Mode Switch to Linear Mode
Hybrid Mode Hybrid Mode
Threaded Mode Switch to Threaded Mode

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Rules
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
BPDU Filter Questions on Global Configuration Mode and Interface Configuration Mode vazurahan Switching 1 08-17-2011 11:11 AM
Reason for multiple subnet in Vlans? eoswins Switching 5 06-13-2011 11:02 PM
Before I Move on lildeezul ISCW 3 12-12-2009 02:08 PM
Spot the difference Andrew Switching 15 12-31-2008 05:01 AM
interVlan routing multiple routers to 1 switch ibanez77 Switching 4 09-14-2008 08:03 AM


All times are GMT -5. The time now is 03:38 AM.

Contact Us - Lammle.com - Archive - Top

Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2013, vBulletin Solutions, Inc.

CCDA, CCDP, CCIE, CCIP, CCNA, CCNP, Cisco, Cisco IOS, Cisco Systems, the Cisco Systems logo, and Networking Academy are registered trademarks or trademarks of Cisco Systems, Inc. and/or its affiliates in the U.S. and certain other countries. All other trademarks mentioned in this document or Web site are the property of their respective owners. The content of this website is the copyrighted property of Lammle.com.
© 2013 Lammle.comPrivacy Policy