<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FTDs in ASA with Inline Sets. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/adding-a-layer2-firewall-between-vlans-with-same-subnet/m-p/3011765#M146450</link>
    <description>&lt;P&gt;FTDs in ASA with Inline Sets. Acts like a bump on the wire, without having to change anything in your current addressing, only cabling.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Or you could do with ASA OS and Firepower in transparent mode. It's not as "invisible" as the FTD with inline mode, but it could do the trick.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Or you can use other products, like 8000 series, 7000 series, which you can be used inline and can do more hardware level things.&lt;/P&gt;</description>
    <pubDate>Thu, 16 Feb 2017 21:24:47 GMT</pubDate>
    <dc:creator>Claudiu Cismaru</dc:creator>
    <dc:date>2017-02-16T21:24:47Z</dc:date>
    <item>
      <title>Adding a layer2 firewall between VLANS with same subnet.</title>
      <link>https://community.cisco.com/t5/network-security/adding-a-layer2-firewall-between-vlans-with-same-subnet/m-p/3011762#M146445</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I'm not a network engineer myself, but will try and communicate this best I can.&amp;nbsp; Please bear with me.&lt;/P&gt;
&lt;P&gt;I have servers on a subnet that I need to segment for security reasons.&amp;nbsp; Currently they are all in a single VLAN.&amp;nbsp; I'd like to complete this segmentation without readdressing.&amp;nbsp; I would like to have a firewall between these segments.&amp;nbsp; Everything is patched into a 4500 switch running in layer 3 mode.&lt;/P&gt;
&lt;P&gt;My idea;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Create new VLANS for the servers to be segmented off, but share the subnet.&lt;/LI&gt;
&lt;LI&gt;Do not allow these VLANs to access each other within the 4500&lt;/LI&gt;
&lt;LI&gt;Present a port on the 4500&amp;nbsp;for each VLAN and connect this to the firewall.&lt;/LI&gt;
&lt;LI&gt;Run the firewall in layer2/transparent/bridging mode to connect the VLANS.&lt;/LI&gt;
&lt;LI&gt;Reconfigure the ports the servers are patched to reflect the VLAN I wish them to be in.&lt;/LI&gt;
&lt;LI&gt;Add rules on firewall the block unwanted traffic between the VLANS.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;I hope that makes sense?&lt;/P&gt;
&lt;P&gt;Is what I am proposing possible?&lt;/P&gt;
&lt;P&gt;Any advice or suggestions welcomed.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Many thanks&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Mark.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 08:56:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/adding-a-layer2-firewall-between-vlans-with-same-subnet/m-p/3011762#M146445</guid>
      <dc:creator>md09</dc:creator>
      <dc:date>2019-03-12T08:56:41Z</dc:date>
    </item>
    <item>
      <title>Each server in own vlan (with</title>
      <link>https://community.cisco.com/t5/network-security/adding-a-layer2-firewall-between-vlans-with-same-subnet/m-p/3011763#M146446</link>
      <description>&lt;P&gt;Each server in own vlan (with /30 mask as a example)&lt;/P&gt;
&lt;P&gt;&lt;SPAN id="result_box" class="" lang="en"&gt;&lt;SPAN&gt;and depending on the&lt;/SPAN&gt; &lt;SPAN&gt;version of the ASA software&lt;/SPAN&gt; &lt;SPAN&gt;to configure&lt;/SPAN&gt; &lt;SPAN&gt;the access rights&lt;/SPAN&gt; &lt;SPAN class=""&gt;between them&lt;/SPAN&gt; &lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN&gt;through&lt;/SPAN&gt; &lt;SPAN class=""&gt;access&lt;/SPAN&gt; &lt;SPAN class=""&gt;lists&lt;/SPAN&gt; &lt;SPAN&gt;or&lt;/SPAN&gt; &lt;SPAN class=""&gt;NAT&lt;/SPAN&gt;&lt;SPAN class=""&gt;)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2017 14:13:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/adding-a-layer2-firewall-between-vlans-with-same-subnet/m-p/3011763#M146446</guid>
      <dc:creator>FrOg Lee</dc:creator>
      <dc:date>2017-02-16T14:13:35Z</dc:date>
    </item>
    <item>
      <title>Thanks for reply FrOg.</title>
      <link>https://community.cisco.com/t5/network-security/adding-a-layer2-firewall-between-vlans-with-same-subnet/m-p/3011764#M146448</link>
      <description>&lt;P&gt;Thanks for reply FrOg.&lt;/P&gt;
&lt;P&gt;So essentially you are saying what I suggest will work?&amp;nbsp; I don't want to segment individual servers, but groups of them.&lt;/P&gt;
&lt;P&gt;MD&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2017 15:33:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/adding-a-layer2-firewall-between-vlans-with-same-subnet/m-p/3011764#M146448</guid>
      <dc:creator>md09</dc:creator>
      <dc:date>2017-02-16T15:33:21Z</dc:date>
    </item>
    <item>
      <title>FTDs in ASA with Inline Sets.</title>
      <link>https://community.cisco.com/t5/network-security/adding-a-layer2-firewall-between-vlans-with-same-subnet/m-p/3011765#M146450</link>
      <description>&lt;P&gt;FTDs in ASA with Inline Sets. Acts like a bump on the wire, without having to change anything in your current addressing, only cabling.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Or you could do with ASA OS and Firepower in transparent mode. It's not as "invisible" as the FTD with inline mode, but it could do the trick.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Or you can use other products, like 8000 series, 7000 series, which you can be used inline and can do more hardware level things.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2017 21:24:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/adding-a-layer2-firewall-between-vlans-with-same-subnet/m-p/3011765#M146450</guid>
      <dc:creator>Claudiu Cismaru</dc:creator>
      <dc:date>2017-02-16T21:24:47Z</dc:date>
    </item>
  </channel>
</rss>

