<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic HI JonThank for the in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/are-firewall-vlan-groups-on-asasm-equal-to-seperate-interfaces-i/m-p/2725821#M177622</link>
    <description>&lt;P&gt;HI Jon&lt;/P&gt;&lt;P&gt;Thank for the clarification!&lt;/P&gt;&lt;P&gt;Frank&lt;/P&gt;</description>
    <pubDate>Mon, 19 Oct 2015 13:06:02 GMT</pubDate>
    <dc:creator>fsebera</dc:creator>
    <dc:date>2015-10-19T13:06:02Z</dc:date>
    <item>
      <title>Are firewall VLAN Groups on ASASM equal to seperate interfaces I.E. DMZs???</title>
      <link>https://community.cisco.com/t5/network-security/are-firewall-vlan-groups-on-asasm-equal-to-seperate-interfaces-i/m-p/2725817#M177618</link>
      <description>&lt;P&gt;&lt;U&gt;Looking for confirmation!!&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;From the Cisco document&lt;/STRONG&gt;:&amp;nbsp;&lt;U&gt;CLI Book 1: Cisco ASA Series General Operations CLI Configuration Guide, 9.1&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;found at URL&lt;/STRONG&gt;: &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa91/configuration/general/asa_91_general_config/intro_switch.html#Assigning" target="_blank"&gt;&lt;SPAN style="color: rgb(178, 34, 34);"&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa91/configuration/general/asa_91_general_config/intro_switch.html#Assigning&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="color: rgb(178, 34, 34);"&gt; VLANs to the ASA Services Module&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: comic sans ms,cursive;"&gt;You can assign up to &lt;STRONG&gt;&lt;U&gt;16 firewall VLAN groups &lt;/U&gt;&lt;/STRONG&gt;to each ASASM. (You can create more than 16 VLAN groups in Cisco IOS software, but only 16 can be assigned per ASASM.) For example, you can assign all the VLANs to one group; or you can create an inside group and an outside group; or you can create a group for each customer.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(0, 0, 205);"&gt;&lt;SPAN style="font-family: georgia,serif;"&gt;MY QUESTION:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(0, 0, 205);"&gt;&lt;SPAN style="font-family: georgia,serif;"&gt;Are the 16 firewall VLAN groups equivalent&amp;nbsp;to&amp;nbsp;16 different interfaces on the ASASM, where each interface could be a separate DMZ and where each separate DMZ could have multiple VLANs?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(0, 0, 205);"&gt;&lt;SPAN style="font-family: georgia,serif;"&gt;THANK YOU&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(0, 0, 205);"&gt;&lt;SPAN style="font-family: georgia,serif;"&gt;Frank&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:45:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/are-firewall-vlan-groups-on-asasm-equal-to-seperate-interfaces-i/m-p/2725817#M177618</guid>
      <dc:creator>fsebera</dc:creator>
      <dc:date>2019-03-12T06:45:50Z</dc:date>
    </item>
    <item>
      <title>FrankI have only used the</title>
      <link>https://community.cisco.com/t5/network-security/are-firewall-vlan-groups-on-asasm-equal-to-seperate-interfaces-i/m-p/2725818#M177619</link>
      <description>&lt;P&gt;Frank&lt;/P&gt;&lt;P&gt;Firstly I have only used the FWSM but I am assuming the principle is the same for the ASASM.&lt;/P&gt;&lt;P&gt;So that said, in answer to your question the vlan groups are not the equivalent of the interfaces on the firewall as that would be a severe limitation.&lt;/P&gt;&lt;P&gt;The vlan groups are used to tell the switch which vlans are allocated to the firewall.&lt;/P&gt;&lt;P&gt;What determines the number of interfaces on the firewall is how many vlans you allocate to the firewall obviously subject to the per context and overall hardware limitations of the ASASM itself ie. there are limits as to how many total vlans it supports and with the FWSM there was also a limit of how many interfaces you could have per context as well.&lt;/P&gt;&lt;P&gt;In terms of using multiple vlan groups I don't think I ever did to be honest although we only had one FWSM per chassis and if you had multiple ASASMs per chassis you may want to use it for organisation.&lt;/P&gt;&lt;P&gt;Or there may just be a limit of how many vlans you can actually assign with a vlan group ie. if the vlans were not sequential it may be there is a limit to the number but then you would just use another vlan group.&lt;/P&gt;&lt;P&gt;That last bit&amp;nbsp;is just supposition though.&lt;/P&gt;&lt;P&gt;But no, as far as I know based on my knowledge of the FWSM, the number of vlan groups does not define the number of interfaces (DMZs) you can have on the ASASM.&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Oct 2015 18:20:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/are-firewall-vlan-groups-on-asasm-equal-to-seperate-interfaces-i/m-p/2725818#M177619</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2015-10-16T18:20:30Z</dc:date>
    </item>
    <item>
      <title>Hi Jon,I think you are saying</title>
      <link>https://community.cisco.com/t5/network-security/are-firewall-vlan-groups-on-asasm-equal-to-seperate-interfaces-i/m-p/2725819#M177620</link>
      <description>&lt;P&gt;Hi Jon,&lt;/P&gt;&lt;P&gt;I think you are saying the VLAN Group feature is used just to inform the ASASM which VLANs the ASASM should create so the ASASM and SWITCH can communicate. Once the ASASM is aware of the VLANs assigned to it, the ASASM will automatically create these VLANs.&amp;nbsp;(a layer-2 sync up). I'm guessing&amp;nbsp;this is sort of like the old Vlan database feature on a Cisco router.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;More digging I guesssss.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Frank&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Oct 2015 19:13:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/are-firewall-vlan-groups-on-asasm-equal-to-seperate-interfaces-i/m-p/2725819#M177620</guid>
      <dc:creator>fsebera</dc:creator>
      <dc:date>2015-10-16T19:13:00Z</dc:date>
    </item>
    <item>
      <title>FrankAgain, based on the FWSM</title>
      <link>https://community.cisco.com/t5/network-security/are-firewall-vlan-groups-on-asasm-equal-to-seperate-interfaces-i/m-p/2725820#M177621</link>
      <description>&lt;P&gt;Frank&lt;/P&gt;&lt;P&gt;Again, based on the FWSM, the module does not create the vlans.&lt;/P&gt;&lt;P&gt;You create vlans in the vlan database just as you would with any other vlan.&lt;/P&gt;&lt;P&gt;The main difference is that for your DMZ vlans you do not create a L3 SVI on the switch because you want the&amp;nbsp;firewall to route traffic.&lt;/P&gt;&lt;P&gt;The vlan group does not tell the ASASM which vlans to create, it simply tells the module which vlans have been assigned to it.&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Fri, 16 Oct 2015 19:26:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/are-firewall-vlan-groups-on-asasm-equal-to-seperate-interfaces-i/m-p/2725820#M177621</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2015-10-16T19:26:59Z</dc:date>
    </item>
    <item>
      <title>HI JonThank for the</title>
      <link>https://community.cisco.com/t5/network-security/are-firewall-vlan-groups-on-asasm-equal-to-seperate-interfaces-i/m-p/2725821#M177622</link>
      <description>&lt;P&gt;HI Jon&lt;/P&gt;&lt;P&gt;Thank for the clarification!&lt;/P&gt;&lt;P&gt;Frank&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2015 13:06:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/are-firewall-vlan-groups-on-asasm-equal-to-seperate-interfaces-i/m-p/2725821#M177622</guid>
      <dc:creator>fsebera</dc:creator>
      <dc:date>2015-10-19T13:06:02Z</dc:date>
    </item>
    <item>
      <title>HI JonThank for the</title>
      <link>https://community.cisco.com/t5/network-security/are-firewall-vlan-groups-on-asasm-equal-to-seperate-interfaces-i/m-p/2725822#M177623</link>
      <description>&lt;P&gt;HI Jon&lt;/P&gt;&lt;P&gt;Thank for the clarification!&lt;/P&gt;&lt;P&gt;Frank&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2015 13:06:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/are-firewall-vlan-groups-on-asasm-equal-to-seperate-interfaces-i/m-p/2725822#M177623</guid>
      <dc:creator>fsebera</dc:creator>
      <dc:date>2015-10-19T13:06:29Z</dc:date>
    </item>
  </channel>
</rss>

