<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA Transparent Mode Deployment Issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-transparent-mode-deployment-issue/m-p/2455302#M270204</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could you please be more specific as to what does not work.&amp;nbsp; How are you testing, from which IP to which IP is not working? Are you able to ping the switch from the ASA Firewall (not the transparent firewall)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-- &lt;BR /&gt;Please remember to rate and select a correct answer&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 06 Feb 2014 09:54:51 GMT</pubDate>
    <dc:creator>Marius Gunnerud</dc:creator>
    <dc:date>2014-02-06T09:54:51Z</dc:date>
    <item>
      <title>ASA Transparent Mode Deployment Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-transparent-mode-deployment-issue/m-p/2455301#M270202</link>
      <description />
      <pubDate>Tue, 12 Mar 2019 03:41:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-transparent-mode-deployment-issue/m-p/2455301#M270202</guid>
      <dc:creator>avilt</dc:creator>
      <dc:date>2019-03-12T03:41:18Z</dc:date>
    </item>
    <item>
      <title>ASA Transparent Mode Deployment Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-transparent-mode-deployment-issue/m-p/2455302#M270204</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could you please be more specific as to what does not work.&amp;nbsp; How are you testing, from which IP to which IP is not working? Are you able to ping the switch from the ASA Firewall (not the transparent firewall)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-- &lt;BR /&gt;Please remember to rate and select a correct answer&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Feb 2014 09:54:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-transparent-mode-deployment-issue/m-p/2455302#M270204</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-02-06T09:54:51Z</dc:date>
    </item>
    <item>
      <title>ASA Transparent Mode Deployment Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-transparent-mode-deployment-issue/m-p/2455303#M270205</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Case 1:&lt;/P&gt;&lt;P&gt;From management PC I can ping 10.10.10.10 &amp;amp; 10.10.10.11 but can not ping 10.10.10.1 or 10.10.20.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Case 2:&lt;/P&gt;&lt;P&gt;Remove ips and directly connect the cable from the switch (gig0/8)to asa firewall (gig0/1) on top. Now I can ping 10.10.10.1 &amp;amp; 10.10.20.2 segment&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Feb 2014 10:03:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-transparent-mode-deployment-issue/m-p/2455303#M270205</guid>
      <dc:creator>avilt</dc:creator>
      <dc:date>2014-02-06T10:03:27Z</dc:date>
    </item>
    <item>
      <title>ASA Transparent Mode Deployment Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-transparent-mode-deployment-issue/m-p/2455304#M270206</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well seems you have found where the issue is yourself.&amp;nbsp; looks like there is a misconfiguration on the IPS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-- &lt;BR /&gt;Please remember to rate and select a correct answer&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Feb 2014 11:18:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-transparent-mode-deployment-issue/m-p/2455304#M270206</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-02-06T11:18:50Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Transparent Mode Deployment Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-transparent-mode-deployment-issue/m-p/2455305#M270208</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could you please point me to the misconfiguration &amp;amp; how to resolve it?&lt;/P&gt;&lt;P&gt;Is the above setup supported?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Feb 2014 11:56:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-transparent-mode-deployment-issue/m-p/2455305#M270208</guid>
      <dc:creator>avilt</dc:creator>
      <dc:date>2014-02-06T11:56:39Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Transparent Mode Deployment Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-transparent-mode-deployment-issue/m-p/2455306#M270210</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well you have it set to fail-open so it is a little strange that it is not allowing traffic through.&amp;nbsp; You could post the IPS config here and we can have a look and see if we can spot anything out of the ordinary.&amp;nbsp; Otherwise, you might also want to&amp;nbsp; post a question in the IPS/IDS section of the support forum.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-- &lt;BR /&gt;Please remember to rate and select a correct answer&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Feb 2014 12:03:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-transparent-mode-deployment-issue/m-p/2455306#M270210</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-02-06T12:03:18Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Transparent Mode Deployment Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-transparent-mode-deployment-issue/m-p/2455307#M270211</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;IPS was set to fail open. I have tried this setup without any vlans and it seems to be working.&lt;/P&gt;&lt;P&gt;I strongly suspect multiple vlan in trnasparant mode will not work as ASA can not inspect vlan tagged packets. Correct me if I am wrong. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Feb 2014 12:23:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-transparent-mode-deployment-issue/m-p/2455307#M270211</guid>
      <dc:creator>avilt</dc:creator>
      <dc:date>2014-02-06T12:23:50Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Transparent Mode Deployment Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-transparent-mode-deployment-issue/m-p/2455308#M270212</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok after a little research I think I have found a solution for you ( I am leaving out the policy map configs):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;firewall transparent&lt;/P&gt;&lt;P&gt;hostname ASA-IPS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0.20&lt;/P&gt;&lt;P&gt; vlan 20&lt;/P&gt;&lt;P&gt; nameif Outside2&lt;/P&gt;&lt;P&gt; bridge-group 2&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0.10&lt;/P&gt;&lt;P&gt; vlan 10&lt;/P&gt;&lt;P&gt; nameif Outside1&lt;/P&gt;&lt;P&gt; bridge-group 1&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1.22&lt;/P&gt;&lt;P&gt; vlan 22&lt;/P&gt;&lt;P&gt; nameif Inside2&lt;/P&gt;&lt;P&gt; bridge-group 2&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1.11&lt;/P&gt;&lt;P&gt; vlan 11&lt;/P&gt;&lt;P&gt; nameif Inside1&lt;/P&gt;&lt;P&gt; bridge-group 1&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface BVI1&lt;/P&gt;&lt;P&gt; ip address 10.10.10.10 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface BVI2&lt;/P&gt;&lt;P&gt; ip address 10.10.20.10 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_acl extended permit ip any any &lt;/P&gt;&lt;P&gt;access-list outside_acl extended permit ip any any &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group outside_acl in interface Outside1&lt;/P&gt;&lt;P&gt;access-group inside_acl in interface Inside1&lt;/P&gt;&lt;P&gt;access-group outside_acl in interface Outside2&lt;/P&gt;&lt;P&gt;access-group inside_acl in interface Inside2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also make sure that you amend the VLANs on the switch to correspond to the VLANs on the Transparent ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-- &lt;BR /&gt;Please remember to rate and select a correct answer&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Feb 2014 12:44:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-transparent-mode-deployment-issue/m-p/2455308#M270212</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-02-06T12:44:36Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Transparent Mode Deployment Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-transparent-mode-deployment-issue/m-p/2455309#M270214</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, I have tried this but not working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But it means I need to create as many vlans &amp;amp; BVI's on ASA that exist in between?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Feb 2014 13:17:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-transparent-mode-deployment-issue/m-p/2455309#M270214</guid>
      <dc:creator>avilt</dc:creator>
      <dc:date>2014-02-06T13:17:31Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Transparent Mode Deployment Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-transparent-mode-deployment-issue/m-p/2455310#M270215</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;But it means I need to create as many vlans &amp;amp; BVI's on ASA that exist in between?&lt;/PRE&gt;&lt;P&gt;From my understanding, yes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-- &lt;BR /&gt;Please remember to rate and select a correct answer&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Feb 2014 13:41:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-transparent-mode-deployment-issue/m-p/2455310#M270215</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-02-06T13:41:49Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Transparent Mode Deployment Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-transparent-mode-deployment-issue/m-p/2455311#M270218</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For me this looks more like a context based firewall. Which BVI IP will be used as ASA source IP? Is it recommended for production environment?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 09 Feb 2014 07:57:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-transparent-mode-deployment-issue/m-p/2455311#M270218</guid>
      <dc:creator>avilt</dc:creator>
      <dc:date>2014-02-09T07:57:33Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Transparent Mode Deployment Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-transparent-mode-deployment-issue/m-p/2455312#M270219</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, it does look much like a context firewall type config.&amp;nbsp; But the config is limited to the number of bridge groups you are able to configure in single mode (this is limited to 8 BVIs).&amp;nbsp; So this solution is not scalable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;Which BVI IP will be used as ASA source IP?&lt;/PRE&gt;&lt;P&gt;Each subnet requires that a BVI is configured with an IP within that subnet, otherwise traffic will be dropped.&amp;nbsp; The source IP will be the BVI that is configured for that specific bridge group.&amp;nbsp; So if you are sending logs to a syslog server out an interface that is in bridge group 1, then the IP of BVI 1 is the source IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt; Is it recommended for production environment?&lt;/PRE&gt;&lt;P&gt;Although I know it is possible to configure the transparent firewall in such a way, I have never seen such a configuration in real life, nor have I ever set it ip in a prod environment.&amp;nbsp; I believe I have never seen it because it is not a scalable solution and&amp;nbsp; will only allow up to 8 VLANs to pass through the tranparent ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have not been able to find any documentation that says that Cisco will support such a configuration, nor have I found documentation say they will not support it.&amp;nbsp; &lt;STRONG&gt;So implement this solution at your own risk&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-- &lt;BR /&gt;Please remember to rate and select a correct answer&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 09 Feb 2014 10:39:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-transparent-mode-deployment-issue/m-p/2455312#M270219</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-02-09T10:39:12Z</dc:date>
    </item>
  </channel>
</rss>

