<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5510 and Sub-Interfaces in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5510-and-sub-interfaces/m-p/2151840#M356675</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sadly I cant comment on the IDS/IPS module as I have never really used it (others in my company have handled that).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Heres a good reference for the ASA firewall models, both "old" and new&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ASA 5500 Series&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/prod_brochure0900aecd80285492.pdf"&gt;http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/prod_brochure0900aecd80285492.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ASA 5500-X Series&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/at_a_glance_c45-701635.pdf"&gt;http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/at_a_glance_c45-701635.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Regarding the Zones/Security-levels/Subinterfaces&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basicly the amount of Subintefaces you can create is only limited by the ASA license. If you look at the above ASA 5500 Series document you will notice that the basic 5510 models supports 50 Vlans and ASA 5510 with Security Plus License supports 100 Vlans. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So in essence you could configure 50/100 Subinterfaces on the ASA depending on your license but naturally at the sametime you can see that performance would most likely become a problem but it would still be possible to configure 50/100 subinterfaces and ACLs to go with them. You could even use 1 single physical interface and bring all of the said Vlans through that same physical interface BUT again this would be far from ideal but still possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can confirm you ASA licensing by using the command "show version". At the end of the list it should state either Base License or Security Plus (if I remember correctly)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hopefully the above information was helpfull &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 13 Feb 2013 14:48:26 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2013-02-13T14:48:26Z</dc:date>
    <item>
      <title>ASA 5510 and Sub-Interfaces</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-and-sub-interfaces/m-p/2151837#M356672</link>
      <description>&lt;P&gt;Can I have eight seperate firewall zones on a 5510 with only 4 ports, and using a Cat 2960 switch?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to have inside, outside, DMZ-1, DMZ-2, DMZ-3, DMZ-4, DMZ-5 and DMZ-6.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can each zone have it's own security level and ACLs?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:00:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-and-sub-interfaces/m-p/2151837#M356672</guid>
      <dc:creator>jimmyc_2</dc:creator>
      <dc:date>2019-03-12T01:00:21Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 and Virtual Interfaces</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-and-sub-interfaces/m-p/2151838#M356673</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you planning on just building a network where the ASA5510 is the gateway for all traffic and behind it you will only have a L2 switch network with Cisco 2960 switches?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If yes, then you can naturally create Vlans for each network segment and configure Trunk/Trunks between the ASA5510 and the closest L2 Switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other possibility is to create a Port-channel (For DMZs) from 2 physical interfaces on the ASA and use the 2 remaning ones and Management for the other purposes. Though Port-channel requires atleast software level 8.4(1) which in turn has the new NAT format and if you have an old ASA5510 then you also might need a RAM upgrade on the ASA. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the ASA side you will have a subinterface for each Vlan ID that you configured on the L2 switches and also their L3 gateway. You can have a separate ACL for each of the interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also one thing to consider in this setup is the performance of the ASA5510. I think its mentioned Throughput is 300Mbps. So take that into account with your setup.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Feb 2013 14:32:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-and-sub-interfaces/m-p/2151838#M356673</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-02-13T14:32:10Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 and Sub-Interfaces</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-and-sub-interfaces/m-p/2151839#M356674</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I meant to say sub-interfaces, not virtual interfaces.&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fortunately, we do have the latest version.&amp;nbsp;&amp;nbsp; I'll look into the throughput issue.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It looks like the bottom line is that the ASA FW can have six zones with only four interfaces. Correct?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can the IDS/IPS module examine all six, or is that limited somehow?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for prompt response.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Feb 2013 14:39:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-and-sub-interfaces/m-p/2151839#M356674</guid>
      <dc:creator>jimmyc_2</dc:creator>
      <dc:date>2013-02-13T14:39:13Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 and Sub-Interfaces</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-and-sub-interfaces/m-p/2151840#M356675</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sadly I cant comment on the IDS/IPS module as I have never really used it (others in my company have handled that).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Heres a good reference for the ASA firewall models, both "old" and new&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ASA 5500 Series&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/prod_brochure0900aecd80285492.pdf"&gt;http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/prod_brochure0900aecd80285492.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ASA 5500-X Series&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/at_a_glance_c45-701635.pdf"&gt;http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/at_a_glance_c45-701635.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Regarding the Zones/Security-levels/Subinterfaces&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basicly the amount of Subintefaces you can create is only limited by the ASA license. If you look at the above ASA 5500 Series document you will notice that the basic 5510 models supports 50 Vlans and ASA 5510 with Security Plus License supports 100 Vlans. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So in essence you could configure 50/100 Subinterfaces on the ASA depending on your license but naturally at the sametime you can see that performance would most likely become a problem but it would still be possible to configure 50/100 subinterfaces and ACLs to go with them. You could even use 1 single physical interface and bring all of the said Vlans through that same physical interface BUT again this would be far from ideal but still possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can confirm you ASA licensing by using the command "show version". At the end of the list it should state either Base License or Security Plus (if I remember correctly)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hopefully the above information was helpfull &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Feb 2013 14:48:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-and-sub-interfaces/m-p/2151840#M356675</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-02-13T14:48:26Z</dc:date>
    </item>
  </channel>
</rss>

