<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic If you're using a Network in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/microsoft-azure-asav-network-design-consideration/m-p/2894865#M171903</link>
    <description>&lt;P&gt;If you're using a Network Virtual Appliance (the ASAv) you don't need to use the Gateway subnet at all. Just assign a Public IP address to one of the ASAv NICs and set up your site-to-site VPN to&amp;nbsp;that Public IP and don't use the Gateway subnet at all. You only need the Gateway subnet when you're using an Azure native gateway for either Azure provided&amp;nbsp;VPN or ExpressRoute gateways.&lt;/P&gt;</description>
    <pubDate>Fri, 01 Jul 2016 22:38:49 GMT</pubDate>
    <dc:creator>jonor0001</dc:creator>
    <dc:date>2016-07-01T22:38:49Z</dc:date>
    <item>
      <title>Microsoft Azure ASAv network design consideration</title>
      <link>https://community.cisco.com/t5/network-security/microsoft-azure-asav-network-design-consideration/m-p/2894862#M171898</link>
      <description>&lt;P&gt;Hi! Since recent availability of ASAv for Microsoft Azure I have question about network design. Currently it is possible to have 4 network interfaces in ASAv, so we limited to 3 subnets in Azure VNET. We have more than 3 subnets and Azure Gateway for S2S connectivity.&lt;BR /&gt;Is it possible to place ASAv inside interface in gateway subnet to substitute azure gateway and provide connectivity to all VNET subnets.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:27:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/microsoft-azure-asav-network-design-consideration/m-p/2894862#M171898</guid>
      <dc:creator>vadim.vedmedenko</dc:creator>
      <dc:date>2019-03-12T07:27:27Z</dc:date>
    </item>
    <item>
      <title>Buy two ASAv's?</title>
      <link>https://community.cisco.com/t5/network-security/microsoft-azure-asav-network-design-consideration/m-p/2894863#M171900</link>
      <description>&lt;P&gt;Buy two ASAv's?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Change to Amazon AWS to get rid of restriction?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Sounds like an awkward problem.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2016 00:01:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/microsoft-azure-asav-network-design-consideration/m-p/2894863#M171900</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2016-03-10T00:01:32Z</dc:date>
    </item>
    <item>
      <title>Philip, thanks for proposals</title>
      <link>https://community.cisco.com/t5/network-security/microsoft-azure-asav-network-design-consideration/m-p/2894864#M171902</link>
      <description>&lt;P&gt;Philip, thanks for proposals I believe that also there are great places outside of our solar system )&lt;/P&gt;
&lt;P&gt;To be close to subject, I asked this to Azure Support and got answer:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;unfortunately the gateway subnet is only destined to Azure gateway.&lt;BR /&gt;We often due some maintenance and upgrades or downgrades to the gateways, and if some more appliances or vm’s were inside that subnet, they could suffer with this operations.&lt;BR /&gt;This is why that type of implementation is not supported.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Thu, 10 Mar 2016 11:03:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/microsoft-azure-asav-network-design-consideration/m-p/2894864#M171902</guid>
      <dc:creator>vadim.vedmedenko</dc:creator>
      <dc:date>2016-03-10T11:03:53Z</dc:date>
    </item>
    <item>
      <title>If you're using a Network</title>
      <link>https://community.cisco.com/t5/network-security/microsoft-azure-asav-network-design-consideration/m-p/2894865#M171903</link>
      <description>&lt;P&gt;If you're using a Network Virtual Appliance (the ASAv) you don't need to use the Gateway subnet at all. Just assign a Public IP address to one of the ASAv NICs and set up your site-to-site VPN to&amp;nbsp;that Public IP and don't use the Gateway subnet at all. You only need the Gateway subnet when you're using an Azure native gateway for either Azure provided&amp;nbsp;VPN or ExpressRoute gateways.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jul 2016 22:38:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/microsoft-azure-asav-network-design-consideration/m-p/2894865#M171903</guid>
      <dc:creator>jonor0001</dc:creator>
      <dc:date>2016-07-01T22:38:49Z</dc:date>
    </item>
    <item>
      <title>Jonor003 you are right but in</title>
      <link>https://community.cisco.com/t5/network-security/microsoft-azure-asav-network-design-consideration/m-p/2894866#M171905</link>
      <description>&lt;P&gt;Jonor003 you are right but in details it's not so simple. Currently you can attach only 3 subnets to ASAv, but we have more than 7.&lt;/P&gt;
&lt;P&gt;You can't attach anything to gateway subnet only Azure gateway can reside there. It's because of redundancy which Azure apply to the their gateway.&lt;/P&gt;</description>
      <pubDate>Sat, 24 Sep 2016 10:00:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/microsoft-azure-asav-network-design-consideration/m-p/2894866#M171905</guid>
      <dc:creator>vadim.vedmedenko</dc:creator>
      <dc:date>2016-09-24T10:00:52Z</dc:date>
    </item>
    <item>
      <title>I am not aware of the subnet</title>
      <link>https://community.cisco.com/t5/network-security/microsoft-azure-asav-network-design-consideration/m-p/2894867#M171907</link>
      <description>&lt;P&gt;I am not aware of the subnet limitation described above in the Azure Virtual Network. This has never been the limitation. Make sure that you have properly assigned your IP Address Space and Subnet Layout to accommodate that Address Space.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2017 22:14:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/microsoft-azure-asav-network-design-consideration/m-p/2894867#M171907</guid>
      <dc:creator>Avery Spates</dc:creator>
      <dc:date>2017-07-24T22:14:53Z</dc:date>
    </item>
    <item>
      <title>Re: Jonor003 you are right but in</title>
      <link>https://community.cisco.com/t5/network-security/microsoft-azure-asav-network-design-consideration/m-p/3801124#M171908</link>
      <description>&lt;P&gt;Hello:&lt;/P&gt;&lt;P&gt;I am really struggling with the ASAv Platform Implementation on Azure.&amp;nbsp; Per the Azure - ASAv Install document, only NIC 0 / Management can be assigned a Public IP Address.&amp;nbsp; Even when I try to assign the same external IP Address via the ssh session, I automatically lose connection to the device and have to try to recover via the Serial Console.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is the expectation to use NIC0 / Management as the Interface launching the IPSec Tunnel? Would you also be able to provide any specific links on establishing a VPN Tunnel?&amp;nbsp; In addition, would I use Static Routing to route between the Management / NIC1 / NIC2 / NIC3 Interfaces?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Feb 2019 16:21:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/microsoft-azure-asav-network-design-consideration/m-p/3801124#M171908</guid>
      <dc:creator>a_mohammed@hotmail.com</dc:creator>
      <dc:date>2019-02-13T16:21:20Z</dc:date>
    </item>
  </channel>
</rss>

