<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic adding a VLAN to ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/adding-a-vlan-to-asa/m-p/2125260#M395605</link>
    <description>&lt;P&gt;I have a very basic ASA that is using the default VLAN1 for internal private subnet and VLAN2 for public subnet.&amp;nbsp; I want to add a third subnet VLAN3 that will be private, security level 100 and NATed out the ASA.&amp;nbsp; I also want to be able to communicate freely between VLAN1 and VLAN3.&amp;nbsp; So question is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Should I use a third physical port configured as access port for VLAN3?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or, should I make the existing VLAN1 port a trunk port and add VLAN3 to it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In either case, if I add, "same-security-traffic permit inter-interface" or "same-security-traffic permit intra-interface" would this be enought to allow both private nets to talk?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Diego&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 00:23:03 GMT</pubDate>
    <dc:creator>tato386</dc:creator>
    <dc:date>2019-03-12T00:23:03Z</dc:date>
    <item>
      <title>adding a VLAN to ASA</title>
      <link>https://community.cisco.com/t5/network-security/adding-a-vlan-to-asa/m-p/2125260#M395605</link>
      <description>&lt;P&gt;I have a very basic ASA that is using the default VLAN1 for internal private subnet and VLAN2 for public subnet.&amp;nbsp; I want to add a third subnet VLAN3 that will be private, security level 100 and NATed out the ASA.&amp;nbsp; I also want to be able to communicate freely between VLAN1 and VLAN3.&amp;nbsp; So question is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Should I use a third physical port configured as access port for VLAN3?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or, should I make the existing VLAN1 port a trunk port and add VLAN3 to it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In either case, if I add, "same-security-traffic permit inter-interface" or "same-security-traffic permit intra-interface" would this be enought to allow both private nets to talk?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Diego&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:23:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/adding-a-vlan-to-asa/m-p/2125260#M395605</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2019-03-12T00:23:03Z</dc:date>
    </item>
    <item>
      <title>adding a VLAN to ASA</title>
      <link>https://community.cisco.com/t5/network-security/adding-a-vlan-to-asa/m-p/2125261#M395606</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Should I use a third physical port configured as access port for VLAN3?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Or, should I make the existing VLAN1 port a trunk port and add VLAN3 to it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; That depends on what you want for your network design,&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;In either case, if I add, "same-security-traffic permit inter-interface" or "same-security-traffic permit intra-interface" would this be enought to allow both private nets to talk?&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Yes, but if you have nat-control on then you will need create some NAT rules to allow traffic back and forward.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Nov 2012 21:08:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/adding-a-vlan-to-asa/m-p/2125261#M395606</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-11-13T21:08:38Z</dc:date>
    </item>
    <item>
      <title>adding a VLAN to ASA</title>
      <link>https://community.cisco.com/t5/network-security/adding-a-vlan-to-asa/m-p/2125262#M395608</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I simply want the two private nets to talk to each other thru the ASA without NAT or rules and for both of the private nets to be NATed to the public.&amp;nbsp; Don't know of any easier way to state that.&amp;nbsp; I guess I want the ASA to be a router?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; The ASA is running 6.3 and I believe the nat-control doesn't come into play until 7.x, no?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Nov 2012 21:17:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/adding-a-vlan-to-asa/m-p/2125262#M395608</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2012-11-13T21:17:27Z</dc:date>
    </item>
    <item>
      <title>adding a VLAN to ASA</title>
      <link>https://community.cisco.com/t5/network-security/adding-a-vlan-to-asa/m-p/2125263#M395610</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Diego,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the ASA version, You just told us 6.3 but that is for ASDM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Okey if that is the case you could use Identity NAT and just the same-security and that will do it&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Nov 2012 21:42:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/adding-a-vlan-to-asa/m-p/2125263#M395610</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-11-13T21:42:16Z</dc:date>
    </item>
    <item>
      <title>adding a VLAN to ASA</title>
      <link>https://community.cisco.com/t5/network-security/adding-a-vlan-to-asa/m-p/2125264#M395612</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Sorry, ASA version is 8.2.&amp;nbsp; What is identify NAT.&amp;nbsp; I have heard the term but not familar with it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Nov 2012 22:36:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/adding-a-vlan-to-asa/m-p/2125264#M395612</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2012-11-13T22:36:17Z</dc:date>
    </item>
    <item>
      <title>adding a VLAN to ASA</title>
      <link>https://community.cisco.com/t5/network-security/adding-a-vlan-to-asa/m-p/2125265#M395614</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is just nat X to X.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So its like translate something to itself&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Nov 2012 22:52:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/adding-a-vlan-to-asa/m-p/2125265#M395614</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-11-13T22:52:09Z</dc:date>
    </item>
  </channel>
</rss>

