<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how asa forward traffic between different vlans in transpare in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-asa-forward-traffic-between-different-vlans-in-transparent/m-p/788430#M1004937</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sebastan &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the key thing to bear in mind is that even though you have 2 vlans you only use 1 ip subnet. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you say in normal circumstances if you have 2 vlans you generally have 2 subnets one per vlan. And then yes the firewall would have to act as router between the 2 subnets. But in transparent mode you stilll have 2 vlans but you have the same IP subnet across both vlans. And the ASA bridges across the 2 vlans. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this makes sense. Please come back with any other questions. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 10 May 2007 05:56:03 GMT</pubDate>
    <dc:creator>Jon Marshall</dc:creator>
    <dc:date>2007-05-10T05:56:03Z</dc:date>
    <item>
      <title>how asa forward traffic between different vlans in transparent mode</title>
      <link>https://community.cisco.com/t5/network-security/how-asa-forward-traffic-between-different-vlans-in-transparent/m-p/788429#M1004936</link>
      <description>&lt;P&gt;hi all i am wondering how does the asa bridge between vlans in transparent mode. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have r1 connetced to asa inside interface and they are configured in vlan 10 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have r2 connected to asa outside and they are in vlan 20.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;till now i have learned for traffic between different vlans needs a routing device in between to forward traffic between them. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here when r1 in vlan 10 is sending traffic destined to vlan 20 how does the asa forward it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cause traffic has to be forward within the same vlan. say for arp. r1 is doing a arp query for r1 which is in different vlan then how does this work. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can someone pls help me out in understanding this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sebastan&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 10:11:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-asa-forward-traffic-between-different-vlans-in-transparent/m-p/788429#M1004936</guid>
      <dc:creator>sebastan_bach</dc:creator>
      <dc:date>2019-03-11T10:11:36Z</dc:date>
    </item>
    <item>
      <title>Re: how asa forward traffic between different vlans in transpare</title>
      <link>https://community.cisco.com/t5/network-security/how-asa-forward-traffic-between-different-vlans-in-transparent/m-p/788430#M1004937</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sebastan &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the key thing to bear in mind is that even though you have 2 vlans you only use 1 ip subnet. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you say in normal circumstances if you have 2 vlans you generally have 2 subnets one per vlan. And then yes the firewall would have to act as router between the 2 subnets. But in transparent mode you stilll have 2 vlans but you have the same IP subnet across both vlans. And the ASA bridges across the 2 vlans. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this makes sense. Please come back with any other questions. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 May 2007 05:56:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-asa-forward-traffic-between-different-vlans-in-transparent/m-p/788430#M1004937</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-05-10T05:56:03Z</dc:date>
    </item>
    <item>
      <title>Re: how asa forward traffic between different vlans in transpare</title>
      <link>https://community.cisco.com/t5/network-security/how-asa-forward-traffic-between-different-vlans-in-transparent/m-p/788431#M1004938</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi jon thanks for ur reply. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i got it and i know this works. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but can u pls tell me anyone one reason or benefit of me configuring vlans in transparent mode. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;waiting for ur reply. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks once again. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sebastan&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 May 2007 11:21:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-asa-forward-traffic-between-different-vlans-in-transparent/m-p/788431#M1004938</guid>
      <dc:creator>sebastan_bach</dc:creator>
      <dc:date>2007-05-10T11:21:30Z</dc:date>
    </item>
    <item>
      <title>Re: how asa forward traffic between different vlans in transpare</title>
      <link>https://community.cisco.com/t5/network-security/how-asa-forward-traffic-between-different-vlans-in-transparent/m-p/788432#M1004939</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sebastan &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Transparent firewalls are useful for a number of things. &lt;/P&gt;&lt;P&gt;Firstly they require no ip address changes to any of your devices as they work at layer 2. &lt;/P&gt;&lt;P&gt;Secondly because they work at layer 2 they are in effect invisible as they are not acting as a layer 3 endpoint.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In addition they can allow a router on one side of the firewall to peer with a firewall on the other side of the firewall via EIGRP/OSPF etc. This can be quite useful in some designs. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 May 2007 11:43:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-asa-forward-traffic-between-different-vlans-in-transparent/m-p/788432#M1004939</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-05-10T11:43:38Z</dc:date>
    </item>
    <item>
      <title>Re: how asa forward traffic between different vlans in transpare</title>
      <link>https://community.cisco.com/t5/network-security/how-asa-forward-traffic-between-different-vlans-in-transparent/m-p/788433#M1004940</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi jon i guess u didn;t get my question right. i know all the benefits of asa in transparent mode. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i was asking what is the need for configuring vlans when asa in transparent mode .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can u pls reply to that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;waiting for ur reply. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sebastan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 May 2007 14:38:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-asa-forward-traffic-between-different-vlans-in-transparent/m-p/788433#M1004940</guid>
      <dc:creator>sebastan_bach</dc:creator>
      <dc:date>2007-05-10T14:38:25Z</dc:date>
    </item>
    <item>
      <title>Re: how asa forward traffic between different vlans in transpare</title>
      <link>https://community.cisco.com/t5/network-security/how-asa-forward-traffic-between-different-vlans-in-transparent/m-p/788434#M1004946</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sebastan &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apologies for misreading the question. Still not 100% sure what you are asking but lets see if this gets any closer. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When a device, be it a load-balancer such as the CSM or an ASA acts in bridge mode you have to have separate vlans on either interface otherwise you are in danger of creating a layer 2 loop in the switched network. If you bridge across the same vlan then you will in effect create a loop so you use 2 vlans but the same IP subnet across both vlans. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this has answered your question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 May 2007 17:38:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-asa-forward-traffic-between-different-vlans-in-transparent/m-p/788434#M1004946</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-05-10T17:38:03Z</dc:date>
    </item>
    <item>
      <title>Re: how asa forward traffic between different vlans in transpare</title>
      <link>https://community.cisco.com/t5/network-security/how-asa-forward-traffic-between-different-vlans-in-transparent/m-p/788435#M1004949</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks jon.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sebastan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 May 2007 09:45:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-asa-forward-traffic-between-different-vlans-in-transparent/m-p/788435#M1004949</guid>
      <dc:creator>sebastan_bach</dc:creator>
      <dc:date>2007-05-11T09:45:22Z</dc:date>
    </item>
  </channel>
</rss>

