<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA5506 New VLAN for Guest WIFI in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa5506-new-vlan-for-guest-wifi/m-p/4075511#M1069566</link>
    <description>&lt;P&gt;You just need to configure a second BVI interface with an IP in the range that VLAN2 has.&lt;/P&gt;
&lt;P&gt;for example:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;interface bvi 1&lt;/P&gt;
&lt;P&gt;nameif inside&lt;/P&gt;
&lt;P&gt;security-level 100&lt;/P&gt;
&lt;P&gt;ip address 10.1.2.1 255.255.255.0 standby 10.1.2.2&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;interface bvi 2&lt;/P&gt;
&lt;P&gt;nameif GUEST-WIFI&lt;/P&gt;
&lt;P&gt;security-level 0&lt;/P&gt;
&lt;P&gt;ip address 10.1.3.1 255.255.255.0 standby 10.1.3.2&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;interface Gig1/1&lt;/P&gt;
&lt;P&gt;description LOCAL_LAN&lt;/P&gt;
&lt;P&gt;bridge-group 1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;interface Gig1/5&lt;/P&gt;
&lt;P&gt;description GUEST_WIFI&lt;/P&gt;
&lt;P&gt;bridge-group 2&lt;/P&gt;</description>
    <pubDate>Tue, 28 Apr 2020 11:41:00 GMT</pubDate>
    <dc:creator>Marius Gunnerud</dc:creator>
    <dc:date>2020-04-28T11:41:00Z</dc:date>
    <item>
      <title>ASA5506 New VLAN for Guest WIFI</title>
      <link>https://community.cisco.com/t5/network-security/asa5506-new-vlan-for-guest-wifi/m-p/4058118#M1068674</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;I need to create new VLAN02 for guest WIFI and set up some rules to restrict access to some IP address.&lt;/P&gt;&lt;P&gt;My ASA5506 is in BVI mode.&lt;/P&gt;&lt;P&gt;The current ASA interfaces are like this;&lt;/P&gt;&lt;P&gt;BVI1 – inside&lt;/P&gt;&lt;P&gt;GIG1/1 -&amp;nbsp; outside -&lt;/P&gt;&lt;P&gt;GIG1/2 -&amp;nbsp; inside_1 -&lt;/P&gt;&lt;P&gt;GIG1/3 -&amp;nbsp; inside_2 -&lt;/P&gt;&lt;P&gt;GIG1/4 -&amp;nbsp; inside_3 -&lt;/P&gt;&lt;P&gt;GIG1/5 -&amp;nbsp; inside_4 -&lt;/P&gt;&lt;P&gt;GIG1/6 -&amp;nbsp; inside_5 -&lt;/P&gt;&lt;P&gt;GIG1/7 -&amp;nbsp; inside_6 -&lt;/P&gt;&lt;P&gt;GIG1/8 -&amp;nbsp; inside_7 -&lt;/P&gt;&lt;P&gt;Management1/1 -&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to assign GIG1/5 for VLAN02 as guest Wi-Fi and assign and IP address for this new VLAN.&lt;/P&gt;&lt;P&gt;What is the best practice to do it? Please.&lt;/P&gt;&lt;P&gt;Is it possible to demonstrate the setting from ASDM?&lt;/P&gt;</description>
      <pubDate>Fri, 03 Apr 2020 05:43:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5506-new-vlan-for-guest-wifi/m-p/4058118#M1068674</guid>
      <dc:creator>saids3</dc:creator>
      <dc:date>2020-04-03T05:43:49Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5506 New VLAN for Guest WIFI</title>
      <link>https://community.cisco.com/t5/network-security/asa5506-new-vlan-for-guest-wifi/m-p/4074776#M1069535</link>
      <description>&lt;P&gt;Hello All&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any feedback? please.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have created "DMZ Name of interface GigabitEthernet1/6.2"&lt;/P&gt;&lt;P&gt;Interface GigabitEthernet1/6.2 "DMZ", is down, line protocol is down&lt;BR /&gt;Hardware is Accelerator rev01, BW 1000 Mbps, DLY 10 usec&lt;BR /&gt;VLAN identifier 2&lt;BR /&gt;MAC address 7488.bb16.a323, MTU 1500&lt;BR /&gt;IP address 10.207.177.1, subnet mask 255.255.255.0&lt;BR /&gt;Traffic Statistics for "DMZ":&lt;BR /&gt;0 packets input, 0 bytes&lt;BR /&gt;0 packets output, 0 bytes&lt;BR /&gt;0 packets dropped&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How to make it active and assign port in cisco switch sg300?&amp;nbsp;&lt;/P&gt;&lt;P&gt;basically for wifi guest.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2020 15:41:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5506-new-vlan-for-guest-wifi/m-p/4074776#M1069535</guid>
      <dc:creator>saids3</dc:creator>
      <dc:date>2020-04-27T15:41:44Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5506 New VLAN for Guest WIFI</title>
      <link>https://community.cisco.com/t5/network-security/asa5506-new-vlan-for-guest-wifi/m-p/4075511#M1069566</link>
      <description>&lt;P&gt;You just need to configure a second BVI interface with an IP in the range that VLAN2 has.&lt;/P&gt;
&lt;P&gt;for example:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;interface bvi 1&lt;/P&gt;
&lt;P&gt;nameif inside&lt;/P&gt;
&lt;P&gt;security-level 100&lt;/P&gt;
&lt;P&gt;ip address 10.1.2.1 255.255.255.0 standby 10.1.2.2&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;interface bvi 2&lt;/P&gt;
&lt;P&gt;nameif GUEST-WIFI&lt;/P&gt;
&lt;P&gt;security-level 0&lt;/P&gt;
&lt;P&gt;ip address 10.1.3.1 255.255.255.0 standby 10.1.3.2&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;interface Gig1/1&lt;/P&gt;
&lt;P&gt;description LOCAL_LAN&lt;/P&gt;
&lt;P&gt;bridge-group 1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;interface Gig1/5&lt;/P&gt;
&lt;P&gt;description GUEST_WIFI&lt;/P&gt;
&lt;P&gt;bridge-group 2&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2020 11:41:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5506-new-vlan-for-guest-wifi/m-p/4075511#M1069566</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-04-28T11:41:00Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5506 New VLAN for Guest WIFI</title>
      <link>https://community.cisco.com/t5/network-security/asa5506-new-vlan-for-guest-wifi/m-p/4075518#M1069568</link>
      <description>&lt;P&gt;Thank you -&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to assign port to this new BVI2&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have cisco switch sg300 28port -&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Steps -&amp;nbsp;&lt;/P&gt;&lt;P&gt;switchbb2d3c#configure t&lt;BR /&gt;switchbb2d3c(config)#interface ge24&lt;BR /&gt;switchbb2d3c(config-if)#switchport mode trunk&lt;BR /&gt;switchbb2d3c(config-if)#switchport trunk allowed &lt;STRONG&gt;vlan add 2&lt;/STRONG&gt;&lt;BR /&gt;switchbb2d3c(config-if)#end&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;switchbb2d3c#configure t&lt;BR /&gt;switchbb2d3c(config)#interface&lt;STRONG&gt; ge 5&lt;/STRONG&gt;&lt;BR /&gt;switchbb2d3c(config-if)#switchport mode access&lt;BR /&gt;switchbb2d3c(config-if)#switchport access &lt;STRONG&gt;vlan 2&lt;/STRONG&gt;&lt;BR /&gt;switchbb2d3c(config-if)#end&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;switchbb2d3c#conf t&lt;BR /&gt;switchbb2d3c(config)#interface&lt;STRONG&gt; ge5&lt;/STRONG&gt;&lt;BR /&gt;switchbb2d3c(config-if)#shutdown&lt;BR /&gt;switchbb2d3c(config-if)#no shutdown&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2020 11:59:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5506-new-vlan-for-guest-wifi/m-p/4075518#M1069568</guid>
      <dc:creator>saids3</dc:creator>
      <dc:date>2020-04-28T11:59:57Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5506 New VLAN for Guest WIFI</title>
      <link>https://community.cisco.com/t5/network-security/asa5506-new-vlan-for-guest-wifi/m-p/4075581#M1069574</link>
      <description>&lt;P&gt;In the example for the BVI interface the switch interface should be an access port.&amp;nbsp; If you want to trunk the switch interface you need to configure subinterfaces on the ASA, assign them to the correct VLAN and add the bridge-group ID.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2020 13:36:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5506-new-vlan-for-guest-wifi/m-p/4075581#M1069574</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-04-28T13:36:39Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5506 New VLAN for Guest WIFI</title>
      <link>https://community.cisco.com/t5/network-security/asa5506-new-vlan-for-guest-wifi/m-p/4075602#M1069576</link>
      <description>&lt;P&gt;So from the firewall side is good so far.&lt;/P&gt;&lt;P&gt;Can you please list the steps for the switch, what I should do?&amp;nbsp;&lt;BR /&gt;Ge24 is the main interface between Asa and switch.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;example I want to assign ge5 to BVI2?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2020 13:59:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5506-new-vlan-for-guest-wifi/m-p/4075602#M1069576</guid>
      <dc:creator>saids3</dc:creator>
      <dc:date>2020-04-28T13:59:24Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5506 New VLAN for Guest WIFI</title>
      <link>https://community.cisco.com/t5/network-security/asa5506-new-vlan-for-guest-wifi/m-p/4075635#M1069579</link>
      <description>&lt;P&gt;What is the reason for using BVI?&amp;nbsp; BVI interface is mainly used when you want to bridge two or more interfaces on the ASA.&amp;nbsp; It is so you can use the ASA interfaces as a switch (of sorts).&amp;nbsp; If you are not using the ASA interfaces as a "switch" then I would suggest not using BVI and just use regular interface configuration.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2020 14:36:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5506-new-vlan-for-guest-wifi/m-p/4075635#M1069579</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-04-28T14:36:04Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5506 New VLAN for Guest WIFI</title>
      <link>https://community.cisco.com/t5/network-security/asa5506-new-vlan-for-guest-wifi/m-p/4075682#M1069582</link>
      <description>&lt;P&gt;Yes, you are right, basically the ASA came with BVI interfaces, I can add normal interface no problem, my question is how to link the switch to the ASA interface assuming the new interface is (VLAN2)?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;appreciated&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2020 15:26:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5506-new-vlan-for-guest-wifi/m-p/4075682#M1069582</guid>
      <dc:creator>saids3</dc:creator>
      <dc:date>2020-04-28T15:26:12Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5506 New VLAN for Guest WIFI</title>
      <link>https://community.cisco.com/t5/network-security/asa5506-new-vlan-for-guest-wifi/m-p/4075741#M1069584</link>
      <description>&lt;P&gt;Assuming that you will have more than one VLAN on the link between ASA and the switch, you can do the following (I am assuming you are following best practice and not using VLAN 1 and therefore I am using VLAN 2 and 3 in this example):&lt;/P&gt;
&lt;P&gt;ASA:&lt;/P&gt;
&lt;P&gt;int Gi1/2&lt;/P&gt;
&lt;P&gt;&amp;nbsp;no shut&lt;/P&gt;
&lt;P&gt;intGi1/2.2&lt;/P&gt;
&lt;P&gt;&amp;nbsp;vlan 2&lt;/P&gt;
&lt;P&gt;&amp;nbsp;nameif WIFI-GUEST&lt;/P&gt;
&lt;P&gt;&amp;nbsp;security-level 5&lt;/P&gt;
&lt;P&gt;ip address 10.1.2.1 255.255.255.0 standby 10.1.2.2&lt;/P&gt;
&lt;P&gt;int Gi1/2.3&lt;/P&gt;
&lt;P&gt;&amp;nbsp;vlan 3&lt;/P&gt;
&lt;P&gt;&amp;nbsp;nameif INSIDE&lt;/P&gt;
&lt;P&gt;&amp;nbsp;security-level 100&lt;/P&gt;
&lt;P&gt;&amp;nbsp;ip address 10.1.3.1 255.255.255.0 standby 10.1.3.2&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;object network WIFI-GUEST-SUBNET&lt;/P&gt;
&lt;P&gt;&amp;nbsp;subnet 10.1.2.0 255.255.255.0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;nat(WIFI-GUEST,OUTSIDE) dynamic interface&lt;/P&gt;
&lt;P&gt;object network INSIDE-SUBNET&lt;/P&gt;
&lt;P&gt;&amp;nbsp;subnet 10.1.3.0 255.255.255.0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;nat(INSIDE,OUTSIDE) dynamic interface&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Switch:&lt;/P&gt;
&lt;P&gt;int Gi1/24&lt;/P&gt;
&lt;P&gt;&amp;nbsp;switchport mode trunk&lt;/P&gt;
&lt;P&gt;&amp;nbsp;switchport trunk allowed vlan add 2,3&lt;/P&gt;
&lt;P&gt;&amp;nbsp;no shut&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2020 16:53:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5506-new-vlan-for-guest-wifi/m-p/4075741#M1069584</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-04-28T16:53:11Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5506 New VLAN for Guest WIFI</title>
      <link>https://community.cisco.com/t5/network-security/asa5506-new-vlan-for-guest-wifi/m-p/4075873#M1069587</link>
      <description>&lt;P&gt;agree&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2020 20:28:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5506-new-vlan-for-guest-wifi/m-p/4075873#M1069587</guid>
      <dc:creator>gerardothink</dc:creator>
      <dc:date>2020-04-28T20:28:02Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5506 New VLAN for Guest WIFI</title>
      <link>https://community.cisco.com/t5/network-security/asa5506-new-vlan-for-guest-wifi/m-p/4076114#M1069606</link>
      <description>&lt;P&gt;Hello -&lt;/P&gt;&lt;P&gt;Thank you for the support, I will make a test and let you know the results.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2020 06:53:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5506-new-vlan-for-guest-wifi/m-p/4076114#M1069606</guid>
      <dc:creator>saids3</dc:creator>
      <dc:date>2020-04-29T06:53:48Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5506 New VLAN for Guest WIFI</title>
      <link>https://community.cisco.com/t5/network-security/asa5506-new-vlan-for-guest-wifi/m-p/4076166#M1069610</link>
      <description>&lt;P&gt;Hello -&amp;nbsp;&lt;/P&gt;&lt;P&gt;90% of work is completed, I can see the new IP Address in the computer -&amp;nbsp;&lt;/P&gt;&lt;P&gt;Things not working,&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. No Internet network access&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. The &lt;STRONG&gt;IPV4 default gateway&lt;/STRONG&gt; is showing different IP Address&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. I'm not able to ping the new IP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IPSETTING.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/73286iCAE14D92E20F7B77/image-size/large?v=v2&amp;amp;px=999" role="button" title="IPSETTING.PNG" alt="IPSETTING.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2020 08:49:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5506-new-vlan-for-guest-wifi/m-p/4076166#M1069610</guid>
      <dc:creator>saids3</dc:creator>
      <dc:date>2020-04-29T08:49:37Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5506 New VLAN for Guest WIFI</title>
      <link>https://community.cisco.com/t5/network-security/asa5506-new-vlan-for-guest-wifi/m-p/4076284#M1069612</link>
      <description>&lt;P&gt;Could you please post the full running configuration of the ASA (remember to remove any public IPs, usernames and passwords).&lt;/P&gt;
&lt;P&gt;Post the output of show route&lt;/P&gt;
&lt;P&gt;Which IP are you not able to ping? The default route IP or the WIFI-GUEST IP?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2020 11:58:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5506-new-vlan-for-guest-wifi/m-p/4076284#M1069612</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-04-29T11:58:09Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5506 New VLAN for Guest WIFI</title>
      <link>https://community.cisco.com/t5/network-security/asa5506-new-vlan-for-guest-wifi/m-p/4076338#M1069619</link>
      <description>&lt;P&gt;at this point, I will have to enter the gate manually -&lt;/P&gt;&lt;P&gt;thank you for the collaboration and excellent support&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2020 13:21:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5506-new-vlan-for-guest-wifi/m-p/4076338#M1069619</guid>
      <dc:creator>saids3</dc:creator>
      <dc:date>2020-04-29T13:21:51Z</dc:date>
    </item>
  </channel>
</rss>

