<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA5508 cant see block traffic between router subinterfaces in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa5508-cant-see-block-traffic-between-router-subinterfaces/m-p/3929682#M24337</link>
    <description>&lt;P&gt;If your device has GW setup in the router, the packet will not reach FW for you to work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you high-level diagram to understand where your FW and how the router setup, where is users IP / Vlan like to block?&lt;/P&gt;</description>
    <pubDate>Tue, 24 Sep 2019 20:07:39 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2019-09-24T20:07:39Z</dc:date>
    <item>
      <title>ASA5508 cant see block traffic between router subinterfaces</title>
      <link>https://community.cisco.com/t5/network-security/asa5508-cant-see-block-traffic-between-router-subinterfaces/m-p/3929566#M24334</link>
      <description>&lt;P&gt;Good Day,&lt;/P&gt;&lt;P&gt;Im currently having an issue where i have my sub interfaces configurated on my router. I also have an ASA5508 that i am using to control traffic. The asa can block traffic between the outside(isp) and inside(internal vlans) with no problem. But if i setup an acl to block traffic between the internal vlans it does not work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I do not even see the traffic flow between the vlans(server vlan to users vlan) in the asa syslogs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can i get some help with this please?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also my current setup is: my isp is plugged into an interface on the asa, my asa is plugged into an interface on the router and my router is plugged into a trunk port on my switch.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2019 16:40:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5508-cant-see-block-traffic-between-router-subinterfaces/m-p/3929566#M24334</guid>
      <dc:creator>ErrolCash0963</dc:creator>
      <dc:date>2019-09-24T16:40:38Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5508 cant see block traffic between router subinterfaces</title>
      <link>https://community.cisco.com/t5/network-security/asa5508-cant-see-block-traffic-between-router-subinterfaces/m-p/3929570#M24335</link>
      <description>&lt;P&gt;VLAN you like to block intervlan blocking, are these interface configured IP address in the FW ? and Devices pointed GW as FW ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if not FW will not aware of that traffic to block.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2019 16:46:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5508-cant-see-block-traffic-between-router-subinterfaces/m-p/3929570#M24335</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2019-09-24T16:46:46Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5508 cant see block traffic between router subinterfaces</title>
      <link>https://community.cisco.com/t5/network-security/asa5508-cant-see-block-traffic-between-router-subinterfaces/m-p/3929583#M24336</link>
      <description>&lt;P&gt;Currently i have the ip address ranges setup as network objects in the FW and i only have the router default gateway set to the FW.&lt;/P&gt;&lt;P&gt;Do my router subinterfaces need to be setup in the FW as interfaces as well?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2019 17:07:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5508-cant-see-block-traffic-between-router-subinterfaces/m-p/3929583#M24336</guid>
      <dc:creator>ErrolCash0963</dc:creator>
      <dc:date>2019-09-24T17:07:43Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5508 cant see block traffic between router subinterfaces</title>
      <link>https://community.cisco.com/t5/network-security/asa5508-cant-see-block-traffic-between-router-subinterfaces/m-p/3929682#M24337</link>
      <description>&lt;P&gt;If your device has GW setup in the router, the packet will not reach FW for you to work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you high-level diagram to understand where your FW and how the router setup, where is users IP / Vlan like to block?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2019 20:07:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5508-cant-see-block-traffic-between-router-subinterfaces/m-p/3929682#M24337</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2019-09-24T20:07:39Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5508 cant see block traffic between router subinterfaces</title>
      <link>https://community.cisco.com/t5/network-security/asa5508-cant-see-block-traffic-between-router-subinterfaces/m-p/3929693#M24338</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Capture.JPG" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/45519iCC36796C099FCC29/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Capture.JPG" alt="Capture.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Please see a high level diagram. My vlans/sub interfaces are setup on the router. There a link going from the router to the follow firewall.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2019 20:21:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5508-cant-see-block-traffic-between-router-subinterfaces/m-p/3929693#M24338</guid>
      <dc:creator>ErrolCash0963</dc:creator>
      <dc:date>2019-09-24T20:21:00Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5508 cant see block traffic between router subinterfaces</title>
      <link>https://community.cisco.com/t5/network-security/asa5508-cant-see-block-traffic-between-router-subinterfaces/m-p/3929773#M24340</link>
      <description>&lt;P&gt;the solution you looking may not work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2019 23:38:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5508-cant-see-block-traffic-between-router-subinterfaces/m-p/3929773#M24340</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2019-09-24T23:38:29Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5508 cant see block traffic between router subinterfaces</title>
      <link>https://community.cisco.com/t5/network-security/asa5508-cant-see-block-traffic-between-router-subinterfaces/m-p/3929914#M24342</link>
      <description>&lt;P&gt;As you are terminating your Hosts and Servers pointing towards a ROUTER ( Router on a stick configuration ) as a Default Gateway. The traffic between Host VLAN and Server VLAN never hit the ASA, hence ASA can not take action and stop. There are few ways you can control the traffic between HOST and Server VLANs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can configure ACLs on the ROUTER (Router on a stick).&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can change the configuration and setup and make ASA as a default Gateway for HOSTs and Servers and than apply ACLs on ASA.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;### RATE ALL HELPFUL RESPONSES ###&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2019 07:49:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5508-cant-see-block-traffic-between-router-subinterfaces/m-p/3929914#M24342</guid>
      <dc:creator>bhargavdesai</dc:creator>
      <dc:date>2019-09-25T07:49:27Z</dc:date>
    </item>
  </channel>
</rss>

