<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Marius,Can I send you a in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/creating-sub-interface-cisco-asa/m-p/2755430#M184274</link>
    <description>&lt;P&gt;Hi Marius,&lt;/P&gt;&lt;P&gt;Can I send you a private P2P?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Thu, 27 Aug 2015 09:22:23 GMT</pubDate>
    <dc:creator>tahirs001</dc:creator>
    <dc:date>2015-08-27T09:22:23Z</dc:date>
    <item>
      <title>Creating Sub-Interface Cisco ASA</title>
      <link>https://community.cisco.com/t5/network-security/creating-sub-interface-cisco-asa/m-p/2755426#M184265</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I need to separate some wireless traffic on a ASA 5520 which is currently hitting our inside network, I would like to move this specific traffic to the DMZ.&lt;/P&gt;&lt;P&gt;Currently I have an Interface named as DMZ, I am looking to create an sub-interface so I can protect this wireless traffic getting to the inside network.&lt;/P&gt;&lt;P&gt;My queries are;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;If I create a sub-interface under the DMZ interface, will I need to remove the existing DMZ interface to create a sub-interface? (what are the best practices on creating a sub-interface)&lt;/LI&gt;&lt;LI&gt;THE DMZ interface is an Access Port on a 3750 switch, which currently allows one VLAN shall I change this to a trunk Port?&lt;/LI&gt;&lt;LI&gt;If you have 2 VLANS on one physical port, how will the VLAN traffic be identified ?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Many Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tahir&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:29:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/creating-sub-interface-cisco-asa/m-p/2755426#M184265</guid>
      <dc:creator>tahirs001</dc:creator>
      <dc:date>2019-03-12T06:29:35Z</dc:date>
    </item>
    <item>
      <title>If I create a sub-interface</title>
      <link>https://community.cisco.com/t5/network-security/creating-sub-interface-cisco-asa/m-p/2755427#M184267</link>
      <description>&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;If I create a sub-interface under the DMZ interface, will I need to remove the existing DMZ interface to create a sub-interface? (what are the best practices on creating a sub-interface)&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;If you intend to have several VLANs terminating on the ASA interface then best practice is to move the DMZ to a subinterface with a specified VLAN.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;THE DMZ interface is an Access Port on a 3750 switch, which currently allows one VLAN shall I change this to a trunk Port?&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Yes this should be confiugred as a trunk port and specify which VLANs are permitted to cross the link by using &lt;STRONG&gt;switchport access vlan allowed&lt;/STRONG&gt; command.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;If you have 2 VLANS on one physical port, how will the VLAN traffic be identified ?&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Not sure what you are trying to get at here.&amp;nbsp; But VLAN traffic is tagged with the VLAN ID when it is sent over the trunk Link.&amp;nbsp; Another reason why you should have the DMZ on a subinterface on the ASA.&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Mon, 24 Aug 2015 21:09:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/creating-sub-interface-cisco-asa/m-p/2755427#M184267</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2015-08-24T21:09:13Z</dc:date>
    </item>
    <item>
      <title>HI Marius,Appreciate the</title>
      <link>https://community.cisco.com/t5/network-security/creating-sub-interface-cisco-asa/m-p/2755428#M184270</link>
      <description>&lt;P&gt;HI Marius,&lt;/P&gt;&lt;P&gt;Appreciate the response.&lt;/P&gt;&lt;P&gt;What I&amp;nbsp;am trying to achieve is to send certain wireless traffic which is picked up by a specific (SSID)&amp;nbsp;into the dmz rather than to the internal network.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At the moment this is working and going to the internal network, and I have been tasked to get this sent to dmz.&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the core switch I have an Interface VLAN315 created with no IP&amp;nbsp;address for this specific ssid traffic, there is also an VLAN created for DMZ VLAN100 which is sending traffic through on int gig/4/0/19 which is an access port (shall I&amp;nbsp;change this to a trunk port and allow VLAN315?&lt;/P&gt;&lt;P&gt;You mentioned in your first comment to move the physical dmz interface to a sub interface, if I&amp;nbsp;do this how pain-free&amp;nbsp;is it to move the existing&amp;nbsp;rules over to&amp;nbsp;the newly created DMZ sub-interface.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2015 13:15:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/creating-sub-interface-cisco-asa/m-p/2755428#M184270</guid>
      <dc:creator>tahirs001</dc:creator>
      <dc:date>2015-08-25T13:15:52Z</dc:date>
    </item>
    <item>
      <title>(shall I change this to a</title>
      <link>https://community.cisco.com/t5/network-security/creating-sub-interface-cisco-asa/m-p/2755429#M184272</link>
      <description>&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;(shall I change this to a trunk port and allow VLAN315?&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;If both VLANs are to terminate on the ASA then yes this port should be a trunk.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;if I do this how pain-free is it to move the existing rules over to the newly created DMZ sub-interface.&amp;nbsp;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;What you should do is take a backup of all configuration that references that interface since all this will be removed once you delete the interface. &amp;nbsp;That would include, but might not be limited to, NAT, static routing, ssh / http managment, dhcp, access-group, etc.&lt;/P&gt;&lt;P&gt;I suggest you first make a configuration template for this interface and all subsequent commands that reference it, so that once you remove the interface it is a quick job of just pasting the config back in ( I am assuming you will not be changing the interface name). &amp;nbsp;This should ofcourse be done in a planned service window and outside of regular working hours.&lt;/P&gt;&lt;P style="font-size: 14.3999996185303px; background-color: rgb(249, 249, 249);"&gt;--&lt;/P&gt;&lt;P style="font-size: 14.3999996185303px; background-color: rgb(249, 249, 249);"&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2015 13:28:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/creating-sub-interface-cisco-asa/m-p/2755429#M184272</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2015-08-25T13:28:36Z</dc:date>
    </item>
    <item>
      <title>Hi Marius,Can I send you a</title>
      <link>https://community.cisco.com/t5/network-security/creating-sub-interface-cisco-asa/m-p/2755430#M184274</link>
      <description>&lt;P&gt;Hi Marius,&lt;/P&gt;&lt;P&gt;Can I send you a private P2P?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2015 09:22:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/creating-sub-interface-cisco-asa/m-p/2755430#M184274</guid>
      <dc:creator>tahirs001</dc:creator>
      <dc:date>2015-08-27T09:22:23Z</dc:date>
    </item>
    <item>
      <title>sure</title>
      <link>https://community.cisco.com/t5/network-security/creating-sub-interface-cisco-asa/m-p/2755431#M184276</link>
      <description>&lt;P&gt;sure&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2015 10:26:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/creating-sub-interface-cisco-asa/m-p/2755431#M184276</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2015-08-27T10:26:18Z</dc:date>
    </item>
  </channel>
</rss>

