<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Marvin in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/issue-on-vlan-1-with-asa-5516-x/m-p/3067571#M135167</link>
    <description>&lt;P&gt;Marvin&lt;/P&gt;
&lt;P&gt;Would this have anything to do with the native vlan and using the physical interface on the ASA ?&lt;/P&gt;
&lt;P&gt;If so to the OP, you can either put the vlan 1 IP address on the physical interface on the ASA or you can change the native vlan to an unused vlan on the trunk ie. on the switch "switchport trunk native vlan &amp;lt;vlan ID&amp;gt;".&lt;/P&gt;
&lt;P&gt;Jon&lt;/P&gt;</description>
    <pubDate>Mon, 29 May 2017 14:58:44 GMT</pubDate>
    <dc:creator>Jon Marshall</dc:creator>
    <dc:date>2017-05-29T14:58:44Z</dc:date>
    <item>
      <title>Issue on VLAN 1 with ASA 5516-X</title>
      <link>https://community.cisco.com/t5/network-security/issue-on-vlan-1-with-asa-5516-x/m-p/3067569#M135159</link>
      <description>&lt;P&gt;Hello Community,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;We have Cisco ASA 5516-X Firepower Threat Defense and connected to Cisco 3850 core switch.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I created VLANs on the 3850 switch and create sub-interface on the ASA 5516-X FTD. My DHCP server is the 3850 switch.&lt;/P&gt;
&lt;P&gt;My issue is VLAN 1 won't work in my setup. I have created other VLANs and work fine. I have VLAN 10 and 11 and works fine, i can get internet connection on these VLAN and can reach each other VLAN. But if a device on the VLAN 1, no internet and cannot reach other VLANs. Cannot also reach the gateway (sub-interface of the ASA 5516-X).&lt;/P&gt;
&lt;P&gt;What need to check?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 09:25:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/issue-on-vlan-1-with-asa-5516-x/m-p/3067569#M135159</guid>
      <dc:creator>VCsupport17</dc:creator>
      <dc:date>2019-03-12T09:25:50Z</dc:date>
    </item>
    <item>
      <title>Here's what I'd start</title>
      <link>https://community.cisco.com/t5/network-security/issue-on-vlan-1-with-asa-5516-x/m-p/3067570#M135164</link>
      <description>&lt;P&gt;Here's what I'd start checking:&lt;/P&gt;
&lt;P&gt;Is the SVI up/up on the switch?&lt;/P&gt;
&lt;P&gt;Does the switch get an ARP entry for the ASA VLAN 1 subinterface?&lt;/P&gt;
&lt;P&gt;Does the ASA get an ARP entry for the SVI?&lt;/P&gt;
&lt;P&gt;Is the trunk from the switch in spanning tree forwarding state for VLAN 1?&lt;/P&gt;</description>
      <pubDate>Mon, 29 May 2017 14:58:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/issue-on-vlan-1-with-asa-5516-x/m-p/3067570#M135164</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-05-29T14:58:43Z</dc:date>
    </item>
    <item>
      <title>Marvin</title>
      <link>https://community.cisco.com/t5/network-security/issue-on-vlan-1-with-asa-5516-x/m-p/3067571#M135167</link>
      <description>&lt;P&gt;Marvin&lt;/P&gt;
&lt;P&gt;Would this have anything to do with the native vlan and using the physical interface on the ASA ?&lt;/P&gt;
&lt;P&gt;If so to the OP, you can either put the vlan 1 IP address on the physical interface on the ASA or you can change the native vlan to an unused vlan on the trunk ie. on the switch "switchport trunk native vlan &amp;lt;vlan ID&amp;gt;".&lt;/P&gt;
&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Mon, 29 May 2017 14:58:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/issue-on-vlan-1-with-asa-5516-x/m-p/3067571#M135167</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2017-05-29T14:58:44Z</dc:date>
    </item>
    <item>
      <title>Ah good point Jon - I think</title>
      <link>https://community.cisco.com/t5/network-security/issue-on-vlan-1-with-asa-5516-x/m-p/3067572#M135170</link>
      <description>&lt;P&gt;Ah good point Jon - I think you may be correct.&lt;/P&gt;
&lt;P&gt;I don't have one handy to lab it up right now but I do recall that the ASA only accepts tagged traffic when you are using subinterfaces. By default VLAN 1 would be untagged from the switch. I found a thread from 10 years back mentioning this:&lt;/P&gt;
&lt;P&gt;https://supportforums.cisco.com/discussion/10113801/how-create-trunk-port-asa-5520&lt;/P&gt;
&lt;P&gt;Your proposed solution makes sense. Setting the native VLAN to anything other than VLAN 1 on the switch side should indicate to it that it must tag VLAN 1 traffic on that trunk.&lt;/P&gt;</description>
      <pubDate>Mon, 29 May 2017 15:35:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/issue-on-vlan-1-with-asa-5516-x/m-p/3067572#M135170</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-05-29T15:35:23Z</dc:date>
    </item>
    <item>
      <title>Hi Jon and Marvin,</title>
      <link>https://community.cisco.com/t5/network-security/issue-on-vlan-1-with-asa-5516-x/m-p/3067573#M135173</link>
      <description>&lt;P&gt;Hi Jon and Marvin,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you for your helpful responses. Now i made my VLAN 1 working after doing your suggestions.&lt;/P&gt;
&lt;P&gt;I remove VLAN 1 on the ASA sub-interface and put it on the Physical interface with its IP address and did work! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/vlan1_0.png" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you for you help.&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2017 04:51:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/issue-on-vlan-1-with-asa-5516-x/m-p/3067573#M135173</guid>
      <dc:creator>VCsupport17</dc:creator>
      <dc:date>2017-05-30T04:51:26Z</dc:date>
    </item>
  </channel>
</rss>

