
3-9
Cisco Security Appliance Command Line Configuration Guide
OL-6721-01
Chapter 3 Enabling Multiple Context Mode
Security Context Overview
Cascading Security Contexts
Because of the limitation for originating traffic on a shared interface, a scenario where you place one
context behind another requires that you configure static statements in the top context for every single
outside address that bottom context users want to access.
Figure 3-5 shows a user in the bottom context (Context A) trying to access www.example.com. Because
the Gateway Context does not have a static translation for www.example.com, the user cannot access the
web server; the classifier does not know which context on the shared interface to assign the packet.
Figure 3-5 Cascading Contexts
Admin
Context
Context A
Gateway
Context
GE 1/1.43
GE 1/1.8
Host
GE 0/0.1
(Shared Interface)
www.example.com
209.165.201.4
HTTP Packet
Dest. Address:
209.165.201.4
IP Address Classifier
Classifier does not know whether
to send packet to Admin, Gateway,
or back to Context A.
Internet
InsideInside
92396
Comentarios a estos manuales