<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Thank you!  You have been a in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5510-with-two-subnets-behind-inside-interface/m-p/2535591#M234931</link>
    <description>&lt;P&gt;Thank you! &amp;nbsp;You have been a great help!&lt;/P&gt;</description>
    <pubDate>Thu, 11 Sep 2014 14:24:06 GMT</pubDate>
    <dc:creator>Albert Succar</dc:creator>
    <dc:date>2014-09-11T14:24:06Z</dc:date>
    <item>
      <title>ASA 5510 with two subnets behind 'inside' interface?</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-two-subnets-behind-inside-interface/m-p/2535583#M234921</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;We currently have an ASA 5510 sitting in front of a catalyst 2960 unmanaged switch.&amp;nbsp; Would it be possible to assign multiple subnets to the inside interface of the ASA&amp;nbsp;without the need to purchase more equipment (an additional router)?&amp;nbsp; I ask&amp;nbsp; because we are in the process of changing our internal subnet and we would like to do so with minimal downtime.&amp;nbsp; So allowing us to have both networks up and slowly transition everything to the new subnet would be our best approach.&amp;nbsp; All help/suggestions is appreciated.&amp;nbsp; Thank you in advance!&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:44:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-two-subnets-behind-inside-interface/m-p/2535583#M234921</guid>
      <dc:creator>Albert Succar</dc:creator>
      <dc:date>2019-03-12T04:44:33Z</dc:date>
    </item>
    <item>
      <title>Sure it is possible.You just</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-two-subnets-behind-inside-interface/m-p/2535584#M234924</link>
      <description>&lt;P&gt;Sure it is possible.&lt;/P&gt;&lt;P&gt;You just need to create subinterfaces on the ASA and place those subinterfaces in their respective VLANs.&amp;nbsp; You also need to trunk the port on the 2960 which connects to the ASA to allow the VLANs to pass over the link.&lt;/P&gt;&lt;P&gt;int gig0/1&lt;BR /&gt;no shut&lt;/P&gt;&lt;P&gt;int gig0/1.10&lt;BR /&gt;vlan 10&lt;BR /&gt;security-level 100&lt;BR /&gt;nameif inside1&lt;BR /&gt;ip add 10.10.10.1 255.255.255.0&lt;/P&gt;&lt;P&gt;int gig0/1.20&lt;BR /&gt;vlan 20&lt;BR /&gt;security-level 100&lt;BR /&gt;nameif inside2&lt;BR /&gt;ip add 20.20.20.1 255.255.255.0&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;As simple as that &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp; Also remember to configure NAT and any required ACLs for the interfaces.&amp;nbsp; If you require help with these just let us know&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Sep 2014 13:17:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-two-subnets-behind-inside-interface/m-p/2535584#M234924</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-09-11T13:17:37Z</dc:date>
    </item>
    <item>
      <title>Thank you for clarifying that</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-two-subnets-behind-inside-interface/m-p/2535585#M234925</link>
      <description>&lt;P&gt;Thank you for clarifying that for me. &amp;nbsp;Currently, here is our inside interface:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;interface Ethernet0/1&lt;BR /&gt;&amp;nbsp;nameif NJinternalIPs&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;ip address 192.168.1.2 255.255.255.0&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;As you can see, no VLAN was setup for this interface. &amp;nbsp;If I was to go with your approach, would I need to create 2 new sub-interfaces with their own associated VLAN? &amp;nbsp;Or could I leave the existing interface and create 1 sub-interface with its own VLAN? &amp;nbsp;I hope I worded that question correctly. &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Sep 2014 13:34:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-two-subnets-behind-inside-interface/m-p/2535585#M234925</guid>
      <dc:creator>Albert Succar</dc:creator>
      <dc:date>2014-09-11T13:34:54Z</dc:date>
    </item>
    <item>
      <title>I have never tested this, So</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-two-subnets-behind-inside-interface/m-p/2535586#M234926</link>
      <description>&lt;P&gt;I have never tested this, So might do so soon &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; , I am not sure if the main interface will be tagged with the native VLAN...So to be on the safe side, I would suggest creating subinterfaces for both VLANs&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Thu, 11 Sep 2014 13:51:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-two-subnets-behind-inside-interface/m-p/2535586#M234926</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-09-11T13:51:22Z</dc:date>
    </item>
    <item>
      <title>Based on what I've been</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-two-subnets-behind-inside-interface/m-p/2535587#M234927</link>
      <description>&lt;P&gt;Based on what I've been reading, this may be the best approach.&lt;/P&gt;&lt;P&gt;There are several switches behind the 2960 switch. &amp;nbsp;Would any configuration need to be done on these switches as-well? &amp;nbsp;Or would I just need to trunk the port going from 2960 -&amp;gt; ASA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Sep 2014 13:56:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-two-subnets-behind-inside-interface/m-p/2535587#M234927</guid>
      <dc:creator>Albert Succar</dc:creator>
      <dc:date>2014-09-11T13:56:12Z</dc:date>
    </item>
    <item>
      <title>You would just need to make</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-two-subnets-behind-inside-interface/m-p/2535588#M234928</link>
      <description>&lt;P&gt;You would just need to make sure that all the required VLANs are trunked to the 2960 switch connected to the ASA and that these same VLANs are also trunked to the ASA, and that the ASA has a subinterface for each VLAN.&lt;/P&gt;&lt;P&gt;And it should go without saying that each subinterface on the ASA will be the default gateway for hosts in their respective VLANs&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Thu, 11 Sep 2014 14:00:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-two-subnets-behind-inside-interface/m-p/2535588#M234928</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-09-11T14:00:09Z</dc:date>
    </item>
    <item>
      <title>Thank you for your help. As</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-two-subnets-behind-inside-interface/m-p/2535589#M234929</link>
      <description>&lt;P&gt;Thank you for your help. As you can tell, I'm fairly new to this process so please bear with me.&lt;/P&gt;&lt;P&gt;If I understand you correctly, all switches behind the 2960 do&amp;nbsp;not need to be adjusted. &amp;nbsp;Host traffic&amp;nbsp;will flow through these switches and hit the 2960. &amp;nbsp;The port going from 2960 to ASA will be trunked and the ASA will have the sub-interfaces configured for each VLAN.&lt;/P&gt;&lt;P&gt;Will I also need to create these VLANS on the switch itself? Again, sorry for the stupid questions. &amp;nbsp;I am trying to get a good understanding before moving forward.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Sep 2014 14:11:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-two-subnets-behind-inside-interface/m-p/2535589#M234929</guid>
      <dc:creator>Albert Succar</dc:creator>
      <dc:date>2014-09-11T14:11:30Z</dc:date>
    </item>
    <item>
      <title>Not to worry, there are no</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-two-subnets-behind-inside-interface/m-p/2535590#M234930</link>
      <description>&lt;P&gt;Not to worry, there are no stupid questions &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The VLANs will need to configured on all the switches and all the ports that connect between the switches need to be trunked.&amp;nbsp; this is important, otherwise the VLAN traffic will not be transported to the next switch.&amp;nbsp; It is possible that this is already done.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;int gig0/1&lt;BR /&gt;description "Link between switches"&lt;BR /&gt;switchport mode trunk&lt;BR /&gt;switchport trunk encapsulation dot1q&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Thu, 11 Sep 2014 14:17:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-two-subnets-behind-inside-interface/m-p/2535590#M234930</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-09-11T14:17:39Z</dc:date>
    </item>
    <item>
      <title>Thank you!  You have been a</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-two-subnets-behind-inside-interface/m-p/2535591#M234931</link>
      <description>&lt;P&gt;Thank you! &amp;nbsp;You have been a great help!&lt;/P&gt;</description>
      <pubDate>Thu, 11 Sep 2014 14:24:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-two-subnets-behind-inside-interface/m-p/2535591#M234931</guid>
      <dc:creator>Albert Succar</dc:creator>
      <dc:date>2014-09-11T14:24:06Z</dc:date>
    </item>
  </channel>
</rss>

