<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA config help in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-config-help/m-p/4442682#M1082645</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1225717"&gt;@Antony_85&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once you put the ASA in transparent mode it will reset the configuration (that is to be expected). You will need direct access to the ASA to configure the bridge group, BVI, ACL and ip address (for mgmt). The plant switch's interface will need to be an access interface, in vlan 20.&lt;/P&gt;</description>
    <pubDate>Mon, 02 Aug 2021 07:16:02 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2021-08-02T07:16:02Z</dc:date>
    <item>
      <title>ASA config help</title>
      <link>https://community.cisco.com/t5/network-security/asa-config-help/m-p/4442615#M1082640</link>
      <description>&lt;P&gt;Hi guys, I was wondering if I could get some assistance from one of the gurus here. I have switch config knowledge but not much ASA config experience. The scenario is as follows (diagram attached)&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Test network.JPG" style="width: 784px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/126815iA51CB61D3B789F0F/image-size/large?v=v2&amp;amp;px=999" role="button" title="Test network.JPG" alt="Test network.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Plant Switch: I don't have access to it. It's managed by the corporate network team. They will configure VLAN20 with a tagged port.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA-5508-X: this is a test ASA not in the production network. Need to put this in TRANSPARENT mode and have ASDM access to it (GUI access). I have put the ASA into transparent but once I do I lose access to ASDM. I set it to factory settings and haven't done any changes yet (have ASDM access back).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2960-CX Test Switch: added VLAN20; ports are configured as ACCESS&lt;/P&gt;&lt;P&gt;Basically need to transfer VLAN 20 traffic through the firewall with no filtering.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Aug 2021 02:03:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-config-help/m-p/4442615#M1082640</guid>
      <dc:creator>Antony_85</dc:creator>
      <dc:date>2021-08-02T02:03:40Z</dc:date>
    </item>
    <item>
      <title>Re: ASA config help</title>
      <link>https://community.cisco.com/t5/network-security/asa-config-help/m-p/4442682#M1082645</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1225717"&gt;@Antony_85&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once you put the ASA in transparent mode it will reset the configuration (that is to be expected). You will need direct access to the ASA to configure the bridge group, BVI, ACL and ip address (for mgmt). The plant switch's interface will need to be an access interface, in vlan 20.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Aug 2021 07:16:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-config-help/m-p/4442682#M1082645</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2021-08-02T07:16:02Z</dc:date>
    </item>
    <item>
      <title>Re: ASA config help</title>
      <link>https://community.cisco.com/t5/network-security/asa-config-help/m-p/4442765#M1082647</link>
      <description>&lt;PRE&gt;Basically need to transfer VLAN 20 traffic through the firewall with no filtering. &lt;/PRE&gt;
&lt;P&gt;Quick question before we can suggest something ? why do you need Transparent FW, if you do not required FW here ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can extend the VLAN to other switch using Trunk right ? what is the challenges here ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Aug 2021 09:28:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-config-help/m-p/4442765#M1082647</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-08-02T09:28:41Z</dc:date>
    </item>
    <item>
      <title>Re: ASA config help</title>
      <link>https://community.cisco.com/t5/network-security/asa-config-help/m-p/4443123#M1082667</link>
      <description>&lt;P&gt;Hi Rob,&lt;/P&gt;&lt;P&gt;Thank you for the response. Could you review if I got the following right? Ones I put the ASA in transparent mode I need to execute !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Switch to transparent mode enable ASDM&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Config-T&lt;/P&gt;&lt;P&gt;Firewall Transparent&lt;/P&gt;&lt;P&gt;Interface bvi-1&lt;/P&gt;&lt;P&gt;Ip address 10.29.96.2 255.255.255.0&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 0.0.0.0 0.0.0.0 inside&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Setting passive mode&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Int e0/0&lt;/P&gt;&lt;P&gt;Switchport access vlan 1&lt;/P&gt;&lt;P&gt;No shutdown&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Int e0/1&lt;/P&gt;&lt;P&gt;Switchport access vlan 20&lt;/P&gt;&lt;P&gt;No shutdown&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interface vlan 1&lt;/P&gt;&lt;P&gt;Nameif outside&lt;/P&gt;&lt;P&gt;Bridge-group 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interface vlan 20&lt;/P&gt;&lt;P&gt;Nameif inside&lt;/P&gt;&lt;P&gt;Bridge-group 1&lt;/P&gt;</description>
      <pubDate>Mon, 02 Aug 2021 23:10:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-config-help/m-p/4443123#M1082667</guid>
      <dc:creator>Antony_85</dc:creator>
      <dc:date>2021-08-02T23:10:42Z</dc:date>
    </item>
    <item>
      <title>Re: ASA config help</title>
      <link>https://community.cisco.com/t5/network-security/asa-config-help/m-p/4443124#M1082668</link>
      <description>&lt;P&gt;Hi Balaji,&lt;/P&gt;&lt;P&gt;Thank you for your response. The plant engineers want a firewall in between the cooperate network and the manufacturing network (2 separate subnets). Some of the PCs connected to VLAN 20 needs access to the cooperate network and some don’t. It will mainly sit as an intrusion detection device.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Aug 2021 23:15:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-config-help/m-p/4443124#M1082668</guid>
      <dc:creator>Antony_85</dc:creator>
      <dc:date>2021-08-02T23:15:24Z</dc:date>
    </item>
    <item>
      <title>Re: ASA config help</title>
      <link>https://community.cisco.com/t5/network-security/asa-config-help/m-p/4443238#M1082670</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1225717"&gt;@Antony_85&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you are using the FW in transparent mode, the 3 devices will need to be in the same network (10.29.96.x), the plant switch in your diagram does not appear to be. You'll also need to consider ACLs.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Aug 2021 07:31:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-config-help/m-p/4443238#M1082670</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2021-08-03T07:31:13Z</dc:date>
    </item>
    <item>
      <title>Re: ASA config help</title>
      <link>https://community.cisco.com/t5/network-security/asa-config-help/m-p/4443326#M1082672</link>
      <description>&lt;P&gt;If you want to extend the VLAN that is fine, You can use FW as Transparent, but i see some difference in IP address range, or do you have same IP range Layer 2 available on the same switch ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Goog example :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.networkstraining.com/cisco-asa-firewall-in-transparent-layer2-mode/" target="_blank"&gt;https://www.networkstraining.com/cisco-asa-firewall-in-transparent-layer2-mode/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Aug 2021 09:37:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-config-help/m-p/4443326#M1082672</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-08-03T09:37:36Z</dc:date>
    </item>
    <item>
      <title>Re: ASA config help</title>
      <link>https://community.cisco.com/t5/network-security/asa-config-help/m-p/4443755#M1082693</link>
      <description>&lt;P&gt;Hi Rob,&lt;/P&gt;&lt;P&gt;I just realize I made a mistake in the diagram. All 3 devices will be in the same subnet. I got the INSIDE working with VALN20 in transparent mode just waiting for the network team to do their part to test further.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had to assign 192.168.1.1 to the Management interface (for ASDM access) because it wouldn't assign a 10.29.96.X IP address to it. Many thanks for the help.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Aug 2021 21:40:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-config-help/m-p/4443755#M1082693</guid>
      <dc:creator>Antony_85</dc:creator>
      <dc:date>2021-08-03T21:40:11Z</dc:date>
    </item>
    <item>
      <title>Re: ASA config help</title>
      <link>https://community.cisco.com/t5/network-security/asa-config-help/m-p/4443758#M1082694</link>
      <description>&lt;P&gt;Hi Balaji,&lt;/P&gt;&lt;P&gt;Thank you for your response. This example is exactly the setup I need. I realize (Rob pointed out) that I made a mistake in my diagram. all 3 devices will be in the same subnet (just like in the example). I managed to get the INSIDE interface working with VLAN20 just waiting for the network team to do their part to test further. Thank you again for the help.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Aug 2021 21:43:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-config-help/m-p/4443758#M1082694</guid>
      <dc:creator>Antony_85</dc:creator>
      <dc:date>2021-08-03T21:43:00Z</dc:date>
    </item>
    <item>
      <title>Re: ASA config help</title>
      <link>https://community.cisco.com/t5/network-security/asa-config-help/m-p/4444018#M1082698</link>
      <description>&lt;P&gt;No worried please keep posted the outcome ..happy to help where we can ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Aug 2021 09:20:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-config-help/m-p/4444018#M1082698</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-08-04T09:20:21Z</dc:date>
    </item>
    <item>
      <title>Re: ASA config help</title>
      <link>https://community.cisco.com/t5/network-security/asa-config-help/m-p/4444523#M1082729</link>
      <description>&lt;P&gt;Thanks, mate,&amp;nbsp;&lt;/P&gt;&lt;P&gt;The network team informed me they configured an Access port so I should be able to test the outcome today. I'll keep you guys posted&lt;/P&gt;</description>
      <pubDate>Wed, 04 Aug 2021 21:42:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-config-help/m-p/4444523#M1082729</guid>
      <dc:creator>Antony_85</dc:creator>
      <dc:date>2021-08-04T21:42:35Z</dc:date>
    </item>
    <item>
      <title>Re: ASA config help</title>
      <link>https://community.cisco.com/t5/network-security/asa-config-help/m-p/4444608#M1082733</link>
      <description>&lt;P&gt;Hay guys,&lt;/P&gt;&lt;P&gt;So it worked. Attached below is my config. Thanks, heaps for all the advice and help. The only issue was I couldn't assign 10.29.96.X to the management interface of the ASA. So had to assign a different subnet but enable ASDM access to INSIDE interface so that works over the network.&lt;/P&gt;&lt;P&gt;Best regards.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="routing1.JPG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/127097i460EA108754B996E/image-size/large?v=v2&amp;amp;px=999" role="button" title="routing1.JPG" alt="routing1.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Aug 2021 04:12:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-config-help/m-p/4444608#M1082733</guid>
      <dc:creator>Antony_85</dc:creator>
      <dc:date>2021-08-05T04:12:13Z</dc:date>
    </item>
    <item>
      <title>Re: ASA config help</title>
      <link>https://community.cisco.com/t5/network-security/asa-config-help/m-p/4444713#M1082737</link>
      <description>&lt;P&gt;Good to know, thank you for the feedback. !&lt;/P&gt;</description>
      <pubDate>Thu, 05 Aug 2021 09:36:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-config-help/m-p/4444713#M1082737</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-08-05T09:36:44Z</dc:date>
    </item>
  </channel>
</rss>

