<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Vlan  subinterface on ASA and connection to internet in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/vlan-subinterface-on-asa-and-connection-to-internet/m-p/2262023#M357656</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Mahesh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For what I can understand from here,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When a host on vlan 20 sends a packet, SW1 or SW2 will receive the traffic with no tags on their access-ports .. &lt;/P&gt;&lt;P&gt;Depending on the host destination IP address&amp;nbsp; the packet&amp;nbsp; will be send to the ASA as this is the 802.1Q routing guy in the picture and the default gateway for them ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ASA has an ARP entry for the IP and MAC address of the ISP router ( The default gateway which is in vlan 10 )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the ASA receives a packet from VLAN 20 that needs to go to an IP address that is unknown to it, it will send it to it's default gateway, checks the IP address and sees that it must go out vlan 10 interface, so it will tag it with a TAG value of 10, it will then reach SW1 with a TAG of 10, it will move like this up to the ISP router,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if I was clear,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 09 May 2013 05:05:42 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2013-05-09T05:05:42Z</dc:date>
    <item>
      <title>Vlan  subinterface on ASA and connection to internet</title>
      <link>https://community.cisco.com/t5/network-security/vlan-subinterface-on-asa-and-connection-to-internet/m-p/2262015#M357648</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Need to understand the network&amp;nbsp; here&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Say we have ASA&amp;nbsp; which has gi0/0 interface and we do subinterfaces of this and it has trunk connection to switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;gi0/0.1 outside&amp;nbsp; vlan 10&lt;/P&gt;&lt;P&gt;gi0/0.2 visitor&amp;nbsp;&amp;nbsp; vlan 20&lt;/P&gt;&lt;P&gt;gi0/0.3 wi fi&amp;nbsp;&amp;nbsp;&amp;nbsp; vlan 30&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;say we have 2 dhcp pools for interface visitor and wi fi.&lt;/P&gt;&lt;P&gt;Say users on visitor dhcp pool has gateway of 192.168&lt;/P&gt;&lt;P&gt;say users on wi fi dhcp pool has gateway of 172.x.x.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;gi 0/0.1 has public ip&amp;nbsp; address and it has default route to edge router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA--------Switch 1------------switch2-------------edge eouter ---------ISP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Switch2 is learning about vlans 10,20,30.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But connection between switch2 and edge router carries only vlan40.&lt;/P&gt;&lt;P&gt;Need to understand how users on vlan 20 and 30 reach the edge router and access the internet as&amp;nbsp; switch2 port connected to edge router carries only&lt;/P&gt;&lt;P&gt;vlan10 as allowed traffic on trunk link?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:41:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-subinterface-on-asa-and-connection-to-internet/m-p/2262015#M357648</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2019-03-12T01:41:00Z</dc:date>
    </item>
    <item>
      <title>Vlan  subinterface on ASA and connection to internet</title>
      <link>https://community.cisco.com/t5/network-security/vlan-subinterface-on-asa-and-connection-to-internet/m-p/2262016#M357649</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Mahesh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you telling us that the trunk port between switch 2 and 1 only allows packets tagged with an 802.1Q header making reference to vlan 40?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question actually would be , is that link a trunk or it's an access port ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cause if it's a trunk it would not be allowed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 May 2013 04:18:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-subinterface-on-asa-and-connection-to-internet/m-p/2262016#M357649</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-05-09T04:18:40Z</dc:date>
    </item>
    <item>
      <title>Vlan  subinterface on ASA and connection to internet</title>
      <link>https://community.cisco.com/t5/network-security/vlan-subinterface-on-asa-and-connection-to-internet/m-p/2262017#M357650</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi julio,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me check on this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 May 2013 04:22:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-subinterface-on-asa-and-connection-to-internet/m-p/2262017#M357650</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2013-05-09T04:22:29Z</dc:date>
    </item>
    <item>
      <title>Vlan  subinterface on ASA and connection to internet</title>
      <link>https://community.cisco.com/t5/network-security/vlan-subinterface-on-asa-and-connection-to-internet/m-p/2262018#M357651</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sure,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;keep me posted&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 May 2013 04:27:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-subinterface-on-asa-and-connection-to-internet/m-p/2262018#M357651</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-05-09T04:27:15Z</dc:date>
    </item>
    <item>
      <title>Vlan  subinterface on ASA and connection to internet</title>
      <link>https://community.cisco.com/t5/network-security/vlan-subinterface-on-asa-and-connection-to-internet/m-p/2262019#M357652</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi julio,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Trunk between switch 1 and 2 carries all the vlan 10,20 and 30&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mahesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 May 2013 04:33:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-subinterface-on-asa-and-connection-to-internet/m-p/2262019#M357652</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2013-05-09T04:33:07Z</dc:date>
    </item>
    <item>
      <title>Vlan  subinterface on ASA and connection to internet</title>
      <link>https://community.cisco.com/t5/network-security/vlan-subinterface-on-asa-and-connection-to-internet/m-p/2262020#M357653</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi julio&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA----------------Trunk vlan 10,20,30 allowed----sw1-------- trunk vlan 10,20,30-------------sw2---------------Trunk only vlan10--edge router&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 May 2013 04:35:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-subinterface-on-asa-and-connection-to-internet/m-p/2262020#M357653</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2013-05-09T04:35:14Z</dc:date>
    </item>
    <item>
      <title>Re: Vlan  subinterface on ASA and connection to internet</title>
      <link>https://community.cisco.com/t5/network-security/vlan-subinterface-on-asa-and-connection-to-internet/m-p/2262021#M357654</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Mahesh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You sure it's a trunk what you are using between switch 2 and Edge router? Is not an access-port?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is the ASA the only device performing 802.1Q routing?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 May 2013 04:46:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-subinterface-on-asa-and-connection-to-internet/m-p/2262021#M357654</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-05-09T04:46:57Z</dc:date>
    </item>
    <item>
      <title>Vlan  subinterface on ASA and connection to internet</title>
      <link>https://community.cisco.com/t5/network-security/vlan-subinterface-on-asa-and-connection-to-internet/m-p/2262022#M357655</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi julio,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;yes there is trunk connection to edge router.&lt;/P&gt;&lt;P&gt;ASA has only static routes no routing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when you say ASA the only device performing 802.1Q routing?&lt;/P&gt;&lt;P&gt;what do you mean?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mahesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 May 2013 04:53:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-subinterface-on-asa-and-connection-to-internet/m-p/2262022#M357655</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2013-05-09T04:53:30Z</dc:date>
    </item>
    <item>
      <title>Re: Vlan  subinterface on ASA and connection to internet</title>
      <link>https://community.cisco.com/t5/network-security/vlan-subinterface-on-asa-and-connection-to-internet/m-p/2262023#M357656</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Mahesh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For what I can understand from here,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When a host on vlan 20 sends a packet, SW1 or SW2 will receive the traffic with no tags on their access-ports .. &lt;/P&gt;&lt;P&gt;Depending on the host destination IP address&amp;nbsp; the packet&amp;nbsp; will be send to the ASA as this is the 802.1Q routing guy in the picture and the default gateway for them ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ASA has an ARP entry for the IP and MAC address of the ISP router ( The default gateway which is in vlan 10 )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the ASA receives a packet from VLAN 20 that needs to go to an IP address that is unknown to it, it will send it to it's default gateway, checks the IP address and sees that it must go out vlan 10 interface, so it will tag it with a TAG value of 10, it will then reach SW1 with a TAG of 10, it will move like this up to the ISP router,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if I was clear,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 May 2013 05:05:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-subinterface-on-asa-and-connection-to-internet/m-p/2262023#M357656</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-05-09T05:05:42Z</dc:date>
    </item>
    <item>
      <title>Vlan  subinterface on ASA and connection to internet</title>
      <link>https://community.cisco.com/t5/network-security/vlan-subinterface-on-asa-and-connection-to-internet/m-p/2262024#M357657</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi julio,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below is my understanding&amp;nbsp; ---&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if i am wrong anywhere---&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The switch 1 and switch 2 have vlan 20,30 where user connect ther PC and access the internet.&lt;/P&gt;&lt;P&gt;Remember&amp;nbsp; switch&amp;nbsp; 1 and 2 does not have SVI&amp;nbsp; vlan 20 and 30.So when user connect to access port vlan 20 or 30 on switch 1 or 2 PC&amp;nbsp; gets IP address from DHCP pool defined on ASA.&lt;/P&gt;&lt;P&gt;&amp;nbsp; and it has default gateway of ASA interface of gi0/0.2 or 0.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When user need to access the internet traffic goes to ASA interface gi0/0.2 as thats default gateway for user PC.&lt;/P&gt;&lt;P&gt;Then ASA has default static route that&amp;nbsp; points to the ASA Edge Router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So traffic from say PC to switch 2 is untagged then from switch 2 to ASA&amp;nbsp; it goes tagged due to trunking.&lt;/P&gt;&lt;P&gt;Then return traffic from ASA&amp;nbsp; to edge router is &lt;/P&gt;&lt;P&gt;ASA&amp;nbsp; to SW1 -----------trunk tagged.&lt;/P&gt;&lt;P&gt;Sw1 to sw2 ----trunk tagged&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sw2 to edge router tagged with vlan 10.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edge router has 802.1q trunking for vlan 10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sw2 to edge router&amp;nbsp; comes as tagged then edge router removes the vlan 10 tag.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 11 May 2013 05:00:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-subinterface-on-asa-and-connection-to-internet/m-p/2262024#M357657</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2013-05-11T05:00:54Z</dc:date>
    </item>
    <item>
      <title>Vlan  subinterface on ASA and connection to internet</title>
      <link>https://community.cisco.com/t5/network-security/vlan-subinterface-on-asa-and-connection-to-internet/m-p/2262025#M357658</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sounds about right to me Mahesh&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Traffic on access ports is not tagged with any Vlan ID&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Traffic on Trunk links is tagged with Vlan ID&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Finally the traffic arriving to the Edge Router removes the tag.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Naturally the way towards the Internet from there depends on how its implemented. Usually there is no subinterfaces involved on the customer side equipment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 11 May 2013 11:26:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-subinterface-on-asa-and-connection-to-internet/m-p/2262025#M357658</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-05-11T11:26:48Z</dc:date>
    </item>
    <item>
      <title>Vlan  subinterface on ASA and connection to internet</title>
      <link>https://community.cisco.com/t5/network-security/vlan-subinterface-on-asa-and-connection-to-internet/m-p/2262026#M357659</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again for confirming me i am correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 11 May 2013 13:47:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-subinterface-on-asa-and-connection-to-internet/m-p/2262026#M357659</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2013-05-11T13:47:21Z</dc:date>
    </item>
  </channel>
</rss>

