<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Transparent Firewall with BVI in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/transparent-firewall-with-bvi/m-p/2137889#M394291</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Franzis and Mariusz,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mariusz that is true but on the newer versions it is possible to split the ASA into different BVIs groups so you can use more than one interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://ciscoasafirewall.blogspot.com/2011/06/cisco-asa-firewall-in-transparent.html"&gt;http://ciscoasafirewall.blogspot.com/2011/06/cisco-asa-firewall-in-transparent.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now how to make that happen Franzis, the outside router will need to perform the routing for you, so traffic must exit the ASA go to an outside layer 3 device and go back to the different brdige group&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 12 Dec 2012 00:46:41 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2012-12-12T00:46:41Z</dc:date>
    <item>
      <title>Transparent Firewall with BVI</title>
      <link>https://community.cisco.com/t5/network-security/transparent-firewall-with-bvi/m-p/2137887#M394287</link>
      <description>&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/1/9/2/118291-Question.png" alt="Question.png" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi! I have a question regarding transparent firewalls using BVIs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Based from the diagram above, ASA1 is in Transparent mode.&lt;/P&gt;&lt;P&gt;Port Gi0 is assigned &lt;EM&gt;BVI-1 &lt;/EM&gt;and port Gi1 is assigned &lt;EM&gt;BVI-2.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible for network 1 to communicate with network 2 ?&lt;/P&gt;&lt;P&gt;The traffic will be passing through Firewall towards the router, The router will do the routing and then forward it back to the firewall then towards network 2?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am thinking of making port Gi2 of the firewall a trunk and use subinterfaces in order to forward BVI headers to the router.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:35:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/transparent-firewall-with-bvi/m-p/2137887#M394287</guid>
      <dc:creator>necxzcisco</dc:creator>
      <dc:date>2019-03-12T00:35:50Z</dc:date>
    </item>
    <item>
      <title>Re: Transparent Firewall with BVI</title>
      <link>https://community.cisco.com/t5/network-security/transparent-firewall-with-bvi/m-p/2137888#M394289</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Franzis,&lt;/P&gt;&lt;P&gt;In transparent mode you can use only two interfaces which have to be on the same subnet:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;LI&gt;&lt;P&gt;- The transparent security appliance uses an inside interface and an outside interface only. If your platform includes a dedicated management interface, you can also configure the management interface or subinterface for management traffic only. &lt;/P&gt;&lt;P&gt;In single mode, you can only use two data interfaces (and the dedicated management interface, if available) even if your security appliance includes more than two interfaces. &lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;- Each directly connected network must be on the same subnet. &lt;/P&gt;&lt;/LI&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Source link:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a008089f467.shtml" rel="nofollow"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a008089f467.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mariusz&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Dec 2012 14:55:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/transparent-firewall-with-bvi/m-p/2137888#M394289</guid>
      <dc:creator>Mariusz Bochen</dc:creator>
      <dc:date>2012-12-11T14:55:45Z</dc:date>
    </item>
    <item>
      <title>Re: Transparent Firewall with BVI</title>
      <link>https://community.cisco.com/t5/network-security/transparent-firewall-with-bvi/m-p/2137889#M394291</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Franzis and Mariusz,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mariusz that is true but on the newer versions it is possible to split the ASA into different BVIs groups so you can use more than one interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://ciscoasafirewall.blogspot.com/2011/06/cisco-asa-firewall-in-transparent.html"&gt;http://ciscoasafirewall.blogspot.com/2011/06/cisco-asa-firewall-in-transparent.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now how to make that happen Franzis, the outside router will need to perform the routing for you, so traffic must exit the ASA go to an outside layer 3 device and go back to the different brdige group&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Dec 2012 00:46:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/transparent-firewall-with-bvi/m-p/2137889#M394291</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-12-12T00:46:41Z</dc:date>
    </item>
    <item>
      <title>Re: Transparent Firewall with BVI</title>
      <link>https://community.cisco.com/t5/network-security/transparent-firewall-with-bvi/m-p/2137890#M394293</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;@jcarvaja&lt;/P&gt;&lt;P&gt;Yes, thank you sir for the reply I have also read that one. That ASA 8.4 and above allows us to use BVI upto 8 I think.&lt;/P&gt;&lt;P&gt;I will be connecting a router to port 4 of the firewall.&lt;/P&gt;&lt;P&gt;My question now is what do I configure in the port Gi2 of the firewall and the port of the router?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried creating sub interfaces in firewall's Gi2 port.&lt;/P&gt;&lt;P&gt;Ex&lt;/P&gt;&lt;P&gt;interface Gi2.10&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Bridge-group 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; vlan 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Gi2.20&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Bridge-group 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; vlan 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is it correct? What do I do with the router's config? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Dec 2012 08:49:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/transparent-firewall-with-bvi/m-p/2137890#M394293</guid>
      <dc:creator>necxzcisco</dc:creator>
      <dc:date>2012-12-12T08:49:50Z</dc:date>
    </item>
    <item>
      <title>Re: Transparent Firewall with BVI</title>
      <link>https://community.cisco.com/t5/network-security/transparent-firewall-with-bvi/m-p/2137891#M394295</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Okay, Why dont you use a dedicated interface for each bridge group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And then on the router use 2 interfaces as well and configure it to route to each subnet pointing to the ASA as you were do regularly,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try that and keep me posted&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Dec 2012 14:15:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/transparent-firewall-with-bvi/m-p/2137891#M394295</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-12-12T14:15:03Z</dc:date>
    </item>
    <item>
      <title>Re: Transparent Firewall with BVI</title>
      <link>https://community.cisco.com/t5/network-security/transparent-firewall-with-bvi/m-p/2137892#M394297</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Okay, I will try it now but I need 3 ports for my Inside and one for the out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll setup my lab again and keep you posted. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Dec 2012 01:11:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/transparent-firewall-with-bvi/m-p/2137892#M394297</guid>
      <dc:creator>necxzcisco</dc:creator>
      <dc:date>2012-12-13T01:11:50Z</dc:date>
    </item>
    <item>
      <title>Re: Transparent Firewall with BVI</title>
      <link>https://community.cisco.com/t5/network-security/transparent-firewall-with-bvi/m-p/2137893#M394299</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Great, let us know the result&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Dec 2012 01:14:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/transparent-firewall-with-bvi/m-p/2137893#M394299</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-12-13T01:14:14Z</dc:date>
    </item>
  </channel>
</rss>

