<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5555 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5555/m-p/4472368#M1083936</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1224107"&gt;@DerekLazarus78183&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So you have L3 switch &amp;gt; ASA &amp;gt; L3 switch?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If each L3 switch has an SVI for the local networks, configure a routed link between the switch and the ASA. Define static routes on the ASA to each network, via the next hop, the ASA won't know about the VLAN IDs. You'll obviously have to permit traffic via an ACL inbound on the ASAs interface.&lt;/P&gt;</description>
    <pubDate>Thu, 23 Sep 2021 19:19:28 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2021-09-23T19:19:28Z</dc:date>
    <item>
      <title>ASA 5555</title>
      <link>https://community.cisco.com/t5/network-security/asa-5555/m-p/4472360#M1083934</link>
      <description>&lt;P&gt;So I have a ASA 5555, coming off it I have a L3 Switch. This switch has its own set of VLANs that I would like to keep seperate from another vlan database on another L3 switch hanging off it as well that houses a seperate network. I would like to be able to monitor the network from one side to the other with NMS software and scans etc. Should I have a router on a stick configuration for the interfaces to allow the vlans to communicate with the inside network for SNMP and other software and how will this interfere with VLANs that may have the same id, wouldn't those machines essentially be able to talk when that is not the intended behavior. I was going for being able to monitor each network but essentially routing to another network allowing each to have their own vlan database without them bleeding into each other.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Sep 2021 19:03:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5555/m-p/4472360#M1083934</guid>
      <dc:creator>DerekLazarus78183</dc:creator>
      <dc:date>2021-09-23T19:03:54Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5555</title>
      <link>https://community.cisco.com/t5/network-security/asa-5555/m-p/4472368#M1083936</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1224107"&gt;@DerekLazarus78183&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So you have L3 switch &amp;gt; ASA &amp;gt; L3 switch?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If each L3 switch has an SVI for the local networks, configure a routed link between the switch and the ASA. Define static routes on the ASA to each network, via the next hop, the ASA won't know about the VLAN IDs. You'll obviously have to permit traffic via an ACL inbound on the ASAs interface.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Sep 2021 19:19:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5555/m-p/4472368#M1083936</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2021-09-23T19:19:28Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5555</title>
      <link>https://community.cisco.com/t5/network-security/asa-5555/m-p/4472411#M1083937</link>
      <description>Yes&lt;BR /&gt;</description>
      <pubDate>Thu, 23 Sep 2021 20:25:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5555/m-p/4472411#M1083937</guid>
      <dc:creator>DerekLazarus78183</dc:creator>
      <dc:date>2021-09-23T20:25:58Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5555</title>
      <link>https://community.cisco.com/t5/network-security/asa-5555/m-p/4473342#M1083955</link>
      <description>&lt;P&gt;I pretty much had already set things up this way turns out there was a software config issue with repositories not being configured for particular subnets after deep diving into everything. Thanks !&lt;/P&gt;</description>
      <pubDate>Fri, 24 Sep 2021 14:39:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5555/m-p/4473342#M1083955</guid>
      <dc:creator>DerekLazarus78183</dc:creator>
      <dc:date>2021-09-24T14:39:18Z</dc:date>
    </item>
  </channel>
</rss>

