<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA5585-X Switchport Trunk ask security expert in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa5585-x-switchport-trunk-ask-security-expert/m-p/2293373#M345824</link>
    <description>&lt;P&gt;Hi, I have ASA5585-X version 9.1 and asdm version 7.1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;have alot of diffrent vlans on the asr router. asr router have a subif with vlans. asa 5585 are behind to asr router. &lt;SPAN style="font-size: 10pt;"&gt;want to setting up asa 5585 switch ports trunk mode. is it possible?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Topology are below.&lt;/P&gt;&lt;P&gt;ISP -&amp;gt; Cisco ASR with bgp and subif and gateway for the vlans -&amp;gt; ASA5585 all ip addresses security configrations -&amp;gt; Cisco 6500 aggregations switch -&amp;gt; Cisco 2960 cabinets switchs -&amp;gt; Servers&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 02:16:52 GMT</pubDate>
    <dc:creator>Umit AYDINLI</dc:creator>
    <dc:date>2019-03-12T02:16:52Z</dc:date>
    <item>
      <title>ASA5585-X Switchport Trunk ask security expert</title>
      <link>https://community.cisco.com/t5/network-security/asa5585-x-switchport-trunk-ask-security-expert/m-p/2293373#M345824</link>
      <description>&lt;P&gt;Hi, I have ASA5585-X version 9.1 and asdm version 7.1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;have alot of diffrent vlans on the asr router. asr router have a subif with vlans. asa 5585 are behind to asr router. &lt;SPAN style="font-size: 10pt;"&gt;want to setting up asa 5585 switch ports trunk mode. is it possible?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Topology are below.&lt;/P&gt;&lt;P&gt;ISP -&amp;gt; Cisco ASR with bgp and subif and gateway for the vlans -&amp;gt; ASA5585 all ip addresses security configrations -&amp;gt; Cisco 6500 aggregations switch -&amp;gt; Cisco 2960 cabinets switchs -&amp;gt; Servers&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:16:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5585-x-switchport-trunk-ask-security-expert/m-p/2293373#M345824</guid>
      <dc:creator>Umit AYDINLI</dc:creator>
      <dc:date>2019-03-12T02:16:52Z</dc:date>
    </item>
    <item>
      <title>ASA5585-X Switchport Trunk ask security expert</title>
      <link>https://community.cisco.com/t5/network-security/asa5585-x-switchport-trunk-ask-security-expert/m-p/2293374#M345827</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can't speak to the ASR router configuration, but you can definitely have trunk ports on the ASA side.&amp;nbsp; What has worked for me between 3750 switches and assorted generations of ASA hardware and software is configurations like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the switch you set it to mode trunk with negotiation off:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/0/38&lt;/P&gt;&lt;P&gt; switchport trunk encapsulation dot1q&lt;/P&gt;&lt;P&gt; switchport trunk native vlan 400&lt;/P&gt;&lt;P&gt; switchport trunk allowed vlan 1,430-435,543-545&lt;/P&gt;&lt;P&gt; switchport mode trunk&lt;/P&gt;&lt;P&gt; switchport nonegotiate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the ASA you put the parent physical interface into "no shutdown" state and then set up subinterfaces with vlan tags:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/3&lt;/P&gt;&lt;P&gt; description trunk port&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/3.543&lt;/P&gt;&lt;P&gt; description first subinterface&lt;/P&gt;&lt;P&gt; vlan 543&lt;/P&gt;&lt;P&gt; nameif whatever&lt;/P&gt;&lt;P&gt; security-level 80&lt;/P&gt;&lt;P&gt; ip address 192.0.2.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-- Jim Leinweber, WI State Lab of Hygiene&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jul 2013 14:07:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5585-x-switchport-trunk-ask-security-expert/m-p/2293374#M345827</guid>
      <dc:creator>James Leinweber</dc:creator>
      <dc:date>2013-07-25T14:07:57Z</dc:date>
    </item>
  </channel>
</rss>

