<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5515 sub-interface question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5515-sub-interface-question/m-p/2112935#M394562</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Eugene,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot for your reply.&lt;/P&gt;&lt;P&gt;My goal here is simple.&lt;/P&gt;&lt;P&gt;I need to configure 5515 exactly the same way as Joebox (less known firewall), for my customer.&lt;/P&gt;&lt;P&gt;Somehow, Joebox has 5 continuous public IP addresses on the physical interface, and I need to configure 5515 the same way. &lt;/P&gt;&lt;P&gt;Those IPs are routed to inside resources through NATing.&lt;/P&gt;&lt;P&gt;Let me know if further information is needed.&lt;/P&gt;&lt;P&gt;Would there be any workaround for this? &lt;/P&gt;&lt;P&gt;Any suggestions would be much appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Young&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 06 Dec 2012 17:34:46 GMT</pubDate>
    <dc:creator>andbartsimpson</dc:creator>
    <dc:date>2012-12-06T17:34:46Z</dc:date>
    <item>
      <title>ASA 5515 sub-interface question</title>
      <link>https://community.cisco.com/t5/network-security/asa-5515-sub-interface-question/m-p/2112932#M394555</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am working on translating configuration from a firewall named Joebox to ASA 5515.&lt;/P&gt;&lt;P&gt;On Joebox, it has 5 continuous public IP addresses (xx.xx.xx.73 -77/29), first one as interface IP and others as alias, on the Internet-facing interface.&lt;/P&gt;&lt;P&gt;I need to configure ASA 5515 in the same way, however it seems not simple.&lt;/P&gt;&lt;P&gt;- The way to configure subinterfaces on 5515 is by configuring VLAN.&lt;/P&gt;&lt;P&gt;- The interface can hold xx.xx.xx.73/29 without a problem. &lt;/P&gt;&lt;P&gt;- The first subinterface can have IP address xx.xx.xx.74 however with different mask(/16), as it doesn’t allow /29.&lt;/P&gt;&lt;P&gt;- The second subinterface doesn’t allow to enter IP xx.xx.xx.75, saying "Failed to apply IP address to interface GigabitEthernet0.x, as the network overlaps with interface GigabitEthernet0. Two interfaces cannot be in the same subnet."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe that there should be a workaround for this.&lt;/P&gt;&lt;P&gt;Can someone please help?&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Young&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:33:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5515-sub-interface-question/m-p/2112932#M394555</guid>
      <dc:creator>andbartsimpson</dc:creator>
      <dc:date>2019-03-12T00:33:50Z</dc:date>
    </item>
    <item>
      <title>ASA 5515 sub-interface question</title>
      <link>https://community.cisco.com/t5/network-security/asa-5515-sub-interface-question/m-p/2112933#M394557</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Young,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can configure Ip addresses on interfaces, only if they are from different subnet. ASA will not allow you to put this commands.&lt;/P&gt;&lt;PRE&gt;&lt;BR /&gt;&lt;P&gt;From subnet 192.168.0.73/29&lt;/P&gt;&lt;SPAN style="color: #009900;"&gt;&lt;SPAN style="color: #000000;"&gt;HostMin:&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="color: #0000ff;"&gt;192.168.0.73&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;&lt;SPAN style="color: #009900;"&gt;&lt;SPAN style="color: #000000;"&gt;HostMax:&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="color: #0000ff;"&gt;192.168.0.78&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, can you please describe what is the purpose of this configuration? What you want to achieve? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate helpful posts &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Eugene&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Dec 2012 16:51:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5515-sub-interface-question/m-p/2112933#M394557</guid>
      <dc:creator>Eugene Korneychuk</dc:creator>
      <dc:date>2012-12-06T16:51:15Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5515 sub-interface question</title>
      <link>https://community.cisco.com/t5/network-security/asa-5515-sub-interface-question/m-p/2112934#M394559</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you are using ASA5515 you are probably running software version 8.6 (confirmable with command "show version")&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I understood you correctly you have a /29 network from the ISP and want to use 1 IP for the "outside" interface and the rest of them as Static NAT IP address for different LAN hosts?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Assuming that the following apply&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;You have one LAN interface called "inside"&lt;/LI&gt;&lt;LI&gt;You have WAN interface called "outside"&lt;/LI&gt;&lt;LI&gt;Your LAN network is 10.10.10.0/24&lt;/LI&gt;&lt;LI&gt;You want Static Public NAT for the following 4 LAN IPs&amp;nbsp;&amp;nbsp; &lt;UL&gt;&lt;LI&gt;10.10.10.10&lt;/LI&gt;&lt;LI&gt;10.10.10.11&lt;/LI&gt;&lt;LI&gt;10.10.10.12&lt;/LI&gt;&lt;LI&gt;10.10.10.13&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your configurations could look something like this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Default PAT for traffic heading to Internet&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group network PAT-SOURCE&lt;/P&gt;&lt;P&gt; description PAT Source Networks&lt;/P&gt;&lt;P&gt; network-object 10.10.10.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (any,outside) after-auto source dynamic PAT-SOURCE interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;The above configuration should make a default PAT rule for outgoing traffic. In other words any client on the LAN that doesnt have own NAT IP configured with Static NAT commands will use the "outside" interface public IP. If you would happen to configure another LAN network behind the ASA you could just add that LAN network under the configured object-group PAT-SOURCE and it would also start using "outside" interface for PAT translation.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Static NAT for servers&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network STATIC-1&lt;/P&gt;&lt;P&gt; host 10.10.10.10&lt;/P&gt;&lt;P&gt; nat (inside,outside) static x.x.x.74 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network STATIC-2&lt;/P&gt;&lt;P&gt; host 10.10.10.11&lt;/P&gt;&lt;P&gt; nat (inside,outside) static x.x.x.75 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network STATIC-3&lt;/P&gt;&lt;P&gt; host 10.10.10.12&lt;/P&gt;&lt;P&gt; nat (inside,outside) static x.x.x.76&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network STATIC-4&lt;/P&gt;&lt;P&gt; host 10.10.10.13&lt;/P&gt;&lt;P&gt; nat (inside,outside) static x.x.x.77&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;The above configures Static NAT for 4 LAN hosts/clients&lt;/LI&gt;&lt;LI&gt;Each Static NAT configuration includes&amp;nbsp;&amp;nbsp; &lt;UL&gt;&lt;LI&gt;object network &lt;NAME&gt; ,under which all the configurations follow&lt;/NAME&gt;&lt;/LI&gt;&lt;LI&gt;host x.x.x.x , which defines the local source address for the Static NAT&lt;/LI&gt;&lt;LI&gt;nat (inside,outside) static x.x.x.x , which defines the source and destination interface for the Static NAT and the actual NAT IP address&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Access-list rules from Internet&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list OUTSIDE-IN permit ip any object STATIC-1&lt;/P&gt;&lt;P&gt;access-list OUTSIDE-IN permit tcp any object STATIC-1 eq &lt;PORT number=""&gt;&lt;/PORT&gt;&lt;/P&gt;&lt;P&gt;access-list OUTSIDE-IN permit udp any object STATIC-1 eq &lt;PORT number=""&gt;&lt;/PORT&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list OUTSIDE-IN permit ip any host 10.10.10.10&lt;/P&gt;&lt;P&gt;access-list OUTSIDE-IN permit tcp any host 10.10.10.10 eq &lt;PORT number=""&gt;&lt;/PORT&gt;&lt;/P&gt;&lt;P&gt;access-list OUTSIDE-IN permit udp any host 10.10.10.10 eq &lt;PORT number=""&gt;&lt;/PORT&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;finally&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group OUTSIDE-IN in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Above are examples of configuring TCP/UDP, TCP or UDP rules to allow traffic with an ACL named OUTSIDE-IN&lt;/LI&gt;&lt;LI&gt;access-group OUTSIDE-IN in interface outside, attaches the ACL to the outside interface. It handles the traffic heading "in" towards the interface.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope the above was of some help. Please rate helpfull posts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Dec 2012 17:34:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5515-sub-interface-question/m-p/2112934#M394559</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-12-06T17:34:30Z</dc:date>
    </item>
    <item>
      <title>ASA 5515 sub-interface question</title>
      <link>https://community.cisco.com/t5/network-security/asa-5515-sub-interface-question/m-p/2112935#M394562</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Eugene,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot for your reply.&lt;/P&gt;&lt;P&gt;My goal here is simple.&lt;/P&gt;&lt;P&gt;I need to configure 5515 exactly the same way as Joebox (less known firewall), for my customer.&lt;/P&gt;&lt;P&gt;Somehow, Joebox has 5 continuous public IP addresses on the physical interface, and I need to configure 5515 the same way. &lt;/P&gt;&lt;P&gt;Those IPs are routed to inside resources through NATing.&lt;/P&gt;&lt;P&gt;Let me know if further information is needed.&lt;/P&gt;&lt;P&gt;Would there be any workaround for this? &lt;/P&gt;&lt;P&gt;Any suggestions would be much appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Young&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Dec 2012 17:34:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5515-sub-interface-question/m-p/2112935#M394562</guid>
      <dc:creator>andbartsimpson</dc:creator>
      <dc:date>2012-12-06T17:34:46Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5515 sub-interface question</title>
      <link>https://community.cisco.com/t5/network-security/asa-5515-sub-interface-question/m-p/2112936#M394564</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;And just to clarify a bit,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You dont configure the addiotional public IP addresses to any interface. You only give the interface its IP address. Rest of the IP addresses only need the NAT commands, nothing else.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Dec 2012 17:39:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5515-sub-interface-question/m-p/2112936#M394564</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-12-06T17:39:53Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5515 sub-interface question</title>
      <link>https://community.cisco.com/t5/network-security/asa-5515-sub-interface-question/m-p/2112937#M394565</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Young,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for clarification,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your ISP will route traffic to your ASA. You do not need to&amp;nbsp; assign the new IP to any interface. You can create statics using the address space and it will work because of the ISP sending the route&amp;nbsp; down to you. Also you need to allow this connections using access-lists&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate helpfull posts &lt;SPAN __jive_emoticon_name="happy"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Dec 2012 17:41:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5515-sub-interface-question/m-p/2112937#M394565</guid>
      <dc:creator>Eugene Korneychuk</dc:creator>
      <dc:date>2012-12-06T17:41:29Z</dc:date>
    </item>
    <item>
      <title>ASA 5515 sub-interface question</title>
      <link>https://community.cisco.com/t5/network-security/asa-5515-sub-interface-question/m-p/2112938#M394567</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you very much Jouni and Eugene.&lt;/P&gt;&lt;P&gt;You guys helped me out, I much*100 appreciate it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Young&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Dec 2012 18:56:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5515-sub-interface-question/m-p/2112938#M394567</guid>
      <dc:creator>andbartsimpson</dc:creator>
      <dc:date>2012-12-06T18:56:10Z</dc:date>
    </item>
  </channel>
</rss>

