<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Thank you very much for your in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/converting-an-existing-interface-on-asa-5510-to-sub-interfaces/m-p/3011003#M135047</link>
    <description>&lt;P&gt;Thank you very much for your reply. &amp;nbsp;I had actually just completed the conversion and was on site so didn't see it when it came in. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;You have explained&amp;nbsp;one issue I experienced. &amp;nbsp;I had forgotten the no nameif command (and so an access rule was still attached to e0/3 and I thought it was because I hadn't removed the group). &amp;nbsp;I've added the no nameif to my cookbook of CLI tasks.&lt;/P&gt;
&lt;P&gt;The switch is a Netgear switch which I had already setup in the main office. &amp;nbsp;All I had to do was plug it in and it was all set up. &amp;nbsp;Thanks to this forum, I had run through a test experiment and the only unknown was using subinterfaces on the ASA 5510 rather than vlan interfaces on the ASA 5505.&lt;/P&gt;
&lt;P&gt;However, we will be upgrading to Cisco switches soon so your config examples are very much appreciated.&lt;/P&gt;
&lt;P&gt;Thanks again for your reply.&lt;/P&gt;</description>
    <pubDate>Tue, 06 Jun 2017 11:26:40 GMT</pubDate>
    <dc:creator>Jean Milne</dc:creator>
    <dc:date>2017-06-06T11:26:40Z</dc:date>
    <item>
      <title>Converting an existing interface on ASA 5510 to sub-interfaces</title>
      <link>https://community.cisco.com/t5/network-security/converting-an-existing-interface-on-asa-5510-to-sub-interfaces/m-p/3010999#M135041</link>
      <description>&lt;P&gt;If a sub interface is added to a currently in-use interface on an ASA 5510, will this bring the interface down?&lt;/P&gt;
&lt;P&gt;The situation is that all 4 of the ports on our production ASA 5510 are currently in use. &amp;nbsp;The overall aim is to add a test DMZ but there is nowhere for it to go.&lt;/P&gt;
&lt;P&gt;The plan is to split the port that is hosting LightsOut traffic into sub-interfaces with their own vlans until the DMZ configuration is complete. &amp;nbsp;Then we will swap the LightsOut traffic back into its own port.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would like to prepare in advance but I don't want to take the interface down until Monday afternoon.&lt;/P&gt;
&lt;P&gt;I have completed an experiment (huge thanks to Jon Marshall) getting multiple vlans working on a single ASA 5505 interface. &amp;nbsp;The ASA 5505 allowed me to create the vlan interfaces in advance and then trunk them when I was ready. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, the setup is different on the ASA 5510.&lt;/P&gt;
&lt;P&gt;Can I add the sub-interfaces now or will that screw up the interface..?&lt;/P&gt;
&lt;P&gt;My apologies if the answer to this is obvious. &amp;nbsp;The documentation wasn't clear and I'd rather not just try it and see.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 09:27:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/converting-an-existing-interface-on-asa-5510-to-sub-interfaces/m-p/3010999#M135041</guid>
      <dc:creator>Jean Milne</dc:creator>
      <dc:date>2019-03-12T09:27:39Z</dc:date>
    </item>
    <item>
      <title>Hello,</title>
      <link>https://community.cisco.com/t5/network-security/converting-an-existing-interface-on-asa-5510-to-sub-interfaces/m-p/3011000#M135042</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;From what I remember, you&amp;nbsp;can't have the main physical interface really configured. If you wanted to add sub-interfaces, you will need to remove any configuration on the physical interface. Preferably set the interface to its default. From there you can create the sub-interfaces and&amp;nbsp;configure security-levels and nameif's under each sub-interface.&lt;/P&gt;
&lt;P&gt;However, make sure you back-up all configurations that are tied the nameif of that interface. I believe once you reset the interface back to default, you will lose all your ACLs n whatnot that are tied to that nameif.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2017 20:08:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/converting-an-existing-interface-on-asa-5510-to-sub-interfaces/m-p/3011000#M135042</guid>
      <dc:creator>dperezoquendo</dc:creator>
      <dc:date>2017-06-02T20:08:02Z</dc:date>
    </item>
    <item>
      <title>Thank you for your reply</title>
      <link>https://community.cisco.com/t5/network-security/converting-an-existing-interface-on-asa-5510-to-sub-interfaces/m-p/3011001#M135044</link>
      <description>&lt;P&gt;Thank you for your reply dperezoquendo. &amp;nbsp;Vey much appreciated (especially the reminder about backing up).&lt;/P&gt;
&lt;P&gt;I have two last questions. &amp;nbsp;I wanted to add the reset you suggested to the beginning but have been unable to find the command..?&lt;/P&gt;
&lt;P&gt;I've googled "asa reset interface" "asa interface remove configuration" and a number of variations but only get articles about resetting the whole device.&lt;/P&gt;
&lt;P&gt;Also, does it matter if you configure the subinterfaces first or the trunk?&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2017 06:48:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/converting-an-existing-interface-on-asa-5510-to-sub-interfaces/m-p/3011001#M135044</guid>
      <dc:creator>Jean Milne</dc:creator>
      <dc:date>2017-06-05T06:48:18Z</dc:date>
    </item>
    <item>
      <title>I'm with dperezoquendo.  In</title>
      <link>https://community.cisco.com/t5/network-security/converting-an-existing-interface-on-asa-5510-to-sub-interfaces/m-p/3011002#M135046</link>
      <description>&lt;P&gt;I'm with dperezoquendo.&amp;nbsp; In my own experience converting from an existing non-trunked interface to one with subinterfaces will require bringing down that interface.&amp;nbsp; I usually reload the entire firewall after overwriting the startup-configuration, as that can be faster than editing back in all the stuff destroyed by removing the original interface.&lt;/P&gt;
&lt;P&gt;On the firewall interface you are converting from access-mode /single use to trunk mode / multiple use, you would do something like:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P style="padding-left: 30px;"&gt;interface Gi0/3&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;no shutdown&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;no nameif&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;no security-level&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;no ip address&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;That "no nameif ..." statement is the one which has the nasty side effects where you destroy all the related NAT, ip reverse-path, mtu, ike, access-group etc. settings.&lt;/P&gt;
&lt;P&gt;On the switch the firewall is connected to, the configuration of the port looks something like:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;switchport trunk encapsulation dot1q&lt;BR /&gt;&amp;nbsp;switchport trunk native vlan NNN&lt;BR /&gt;&amp;nbsp;switchport trunk allowed vlan 1,XXX,YYY&lt;BR /&gt;&amp;nbsp;switchport mode trunk&lt;BR /&gt;&amp;nbsp;switchport nonegotiate&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;You have to replace NNN, XXX, and YYY with appropriate vlan tags from your environment.&amp;nbsp; The native vlan should be entirely unused for anything except that.&amp;nbsp; Back at the ASA, the subinterface configuration look something like:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;interface Gi0/3.XXX&lt;/P&gt;
&lt;P&gt;vlan XXX&lt;/P&gt;
&lt;P&gt;...&lt;/P&gt;
&lt;P&gt;interface Gi0/3.YYY&lt;/P&gt;
&lt;P&gt;vlan YYY&lt;/P&gt;
&lt;P&gt;...&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;I don't think it matters which order you do the switch and the firewall in, though I tend to do the switch first.&amp;nbsp; If you do the firewall first you might need do shutdown the parent physical interface and bring it back up after fixing the switchport.&amp;nbsp; The dot1q and nonegotiate settings on the switchport are key to successful communication with the ASA firewall; it is inflexible and unconfigurable for anything else.&lt;/P&gt;
&lt;P&gt;Good luck with the conversion,&lt;/P&gt;
&lt;P&gt;-- Jim Leinweber, WI State Lab of Hygiene&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2017 17:32:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/converting-an-existing-interface-on-asa-5510-to-sub-interfaces/m-p/3011002#M135046</guid>
      <dc:creator>James Leinweber</dc:creator>
      <dc:date>2017-06-05T17:32:27Z</dc:date>
    </item>
    <item>
      <title>Thank you very much for your</title>
      <link>https://community.cisco.com/t5/network-security/converting-an-existing-interface-on-asa-5510-to-sub-interfaces/m-p/3011003#M135047</link>
      <description>&lt;P&gt;Thank you very much for your reply. &amp;nbsp;I had actually just completed the conversion and was on site so didn't see it when it came in. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;You have explained&amp;nbsp;one issue I experienced. &amp;nbsp;I had forgotten the no nameif command (and so an access rule was still attached to e0/3 and I thought it was because I hadn't removed the group). &amp;nbsp;I've added the no nameif to my cookbook of CLI tasks.&lt;/P&gt;
&lt;P&gt;The switch is a Netgear switch which I had already setup in the main office. &amp;nbsp;All I had to do was plug it in and it was all set up. &amp;nbsp;Thanks to this forum, I had run through a test experiment and the only unknown was using subinterfaces on the ASA 5510 rather than vlan interfaces on the ASA 5505.&lt;/P&gt;
&lt;P&gt;However, we will be upgrading to Cisco switches soon so your config examples are very much appreciated.&lt;/P&gt;
&lt;P&gt;Thanks again for your reply.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2017 11:26:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/converting-an-existing-interface-on-asa-5510-to-sub-interfaces/m-p/3011003#M135047</guid>
      <dc:creator>Jean Milne</dc:creator>
      <dc:date>2017-06-06T11:26:40Z</dc:date>
    </item>
  </channel>
</rss>

