<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Thanks Akshay. I should've in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/figure-out-connected-vlan/m-p/2775125#M174471</link>
    <description>&lt;P&gt;Thanks Akshay. I should've clarified in my post - the ASA does not have config on relating to the 2960X - it's a new ASA, connecting to a 2960X which has been taken from another site and someone has changed some of the configuration on it... nightmare!&lt;/P&gt;</description>
    <pubDate>Mon, 30 Nov 2015 09:35:06 GMT</pubDate>
    <dc:creator>noisey_uk</dc:creator>
    <dc:date>2015-11-30T09:35:06Z</dc:date>
    <item>
      <title>Figure out connected VLAN</title>
      <link>https://community.cisco.com/t5/network-security/figure-out-connected-vlan/m-p/2775121#M174464</link>
      <description>&lt;P&gt;An ASA5515-X is sucessfully connected to a 2960X via an LACP port-channel. Someone has changed the config on the 2960X end of the port-channel so we've no idea which VLANs are being trunked or the IP addresses of the management SVI on said switch. The switch is half way across the world and local resources are not great technically so, clutching at straws, can anyone think of a way of finding out the VLANs/IP involved? I've put this in Firewalling as I'd have thought a debug command on the ASA is the biggest hope...&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:57:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/figure-out-connected-vlan/m-p/2775121#M174464</guid>
      <dc:creator>noisey_uk</dc:creator>
      <dc:date>2019-03-12T06:57:46Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/figure-out-connected-vlan/m-p/2775122#M174466</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;You can try your luck with sub-interfaces created on ASA from that port channel. Check the subnet configured on those interfaces. Also check the routes on ASA with 'show route' this would show you connected routes. With this you could get the idea of the subnet connected to it. Also it would show you the next hop for those subnets. As you have mentioned that SVI is configured on switch so i believe that next hop would be the SVI on switch.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hope it helps.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Akshay Rastogi&lt;/P&gt;
&lt;P&gt;Remember to rate helpful posts.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Nov 2015 05:13:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/figure-out-connected-vlan/m-p/2775122#M174466</guid>
      <dc:creator>Akshay Rastogi</dc:creator>
      <dc:date>2015-11-29T05:13:08Z</dc:date>
    </item>
    <item>
      <title>You might be able to</title>
      <link>https://community.cisco.com/t5/network-security/figure-out-connected-vlan/m-p/2775123#M174467</link>
      <description>&lt;P&gt;You might be able to ascertain the information by doi ng a packet capture on the ASA inside interface and examining the LACP bits.&lt;/P&gt;
&lt;P&gt;You might also get the switch address from the CDP neighbor advertisements. Even though the ASA doesn't participate in CDP per se, it will still see the Layer 2 CDP broadcasts at the packet level.&lt;/P&gt;</description>
      <pubDate>Sun, 29 Nov 2015 14:22:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/figure-out-connected-vlan/m-p/2775123#M174467</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-11-29T14:22:20Z</dc:date>
    </item>
    <item>
      <title>Thanks for your input Marvin.</title>
      <link>https://community.cisco.com/t5/network-security/figure-out-connected-vlan/m-p/2775124#M174469</link>
      <description>&lt;P&gt;Thanks for your input&amp;nbsp;Marvin. Packet capture is half the answer I think as it would rely&amp;nbsp;on configuring the ASA subinterface with the VLAN ID that matches the corresponding switch VLAN... which I don't know. I guess I'm after a more thorough capture&amp;nbsp;capability, like Wireshark, built into the ASA. Might still be a bit of trial and error involved I think. Relieved&amp;nbsp;this is T&amp;amp;M...!&lt;/P&gt;</description>
      <pubDate>Mon, 30 Nov 2015 09:31:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/figure-out-connected-vlan/m-p/2775124#M174469</guid>
      <dc:creator>noisey_uk</dc:creator>
      <dc:date>2015-11-30T09:31:10Z</dc:date>
    </item>
    <item>
      <title>Thanks Akshay. I should've</title>
      <link>https://community.cisco.com/t5/network-security/figure-out-connected-vlan/m-p/2775125#M174471</link>
      <description>&lt;P&gt;Thanks Akshay. I should've clarified in my post - the ASA does not have config on relating to the 2960X - it's a new ASA, connecting to a 2960X which has been taken from another site and someone has changed some of the configuration on it... nightmare!&lt;/P&gt;</description>
      <pubDate>Mon, 30 Nov 2015 09:35:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/figure-out-connected-vlan/m-p/2775125#M174471</guid>
      <dc:creator>noisey_uk</dc:creator>
      <dc:date>2015-11-30T09:35:06Z</dc:date>
    </item>
    <item>
      <title>Noisey,</title>
      <link>https://community.cisco.com/t5/network-security/figure-out-connected-vlan/m-p/2775126#M174473</link>
      <description>&lt;P&gt;Noisey,&lt;/P&gt;
&lt;P&gt;You only need the subinterface ID in order to complete LACP negotiation. Without it, you will still se the switch's offered VLAN tags on the trunking establishment messages (even though the trunk won't establoish until the ASA matches).&lt;/P&gt;</description>
      <pubDate>Mon, 30 Nov 2015 13:31:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/figure-out-connected-vlan/m-p/2775126#M174473</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-11-30T13:31:20Z</dc:date>
    </item>
  </channel>
</rss>

