<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need help with 5505 layout in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/need-help-with-5505-layout/m-p/2042656#M398017</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not sure I follow you.&lt;/P&gt;&lt;P&gt;You can configure a trunk from the switch to the Asa then do&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/1.2&lt;/P&gt;&lt;P&gt; vlan 2&lt;/P&gt;&lt;P&gt; nameif Insidelan2&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.2.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 07 Oct 2012 22:13:44 GMT</pubDate>
    <dc:creator>Stuart Gall</dc:creator>
    <dc:date>2012-10-07T22:13:44Z</dc:date>
    <item>
      <title>Need help with 5505 layout</title>
      <link>https://community.cisco.com/t5/network-security/need-help-with-5505-layout/m-p/2042655#M398016</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Need to re-design our network layout to accompany guest networks and some seperate vlans.&amp;nbsp; Currently we are 1 vlan connected directly from a 2950 to a 5505 asa.&amp;nbsp; I would like keep vlan 1 the same so I dont have to reconfigure all of our statics on the pc.. so basicly here is our setup&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2950 ---------------&amp;gt;asa5505 (192.168.1.1)&lt;/P&gt;&lt;P&gt;switch&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; vlan 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;192.168.1.x /24&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what i would like to do is this&lt;/P&gt;&lt;P&gt;3560---------&amp;gt;asa5505 &lt;/P&gt;&lt;P&gt;with vlans 1,2,3,4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but as far as the connectivity between the 3560 and the asa is where i get lost... since technically the 5505 is defined for layer 2, what is the best way to get from the 3560 to the asa.?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any help would be much appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:05:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-with-5505-layout/m-p/2042655#M398016</guid>
      <dc:creator>Joe Lentine</dc:creator>
      <dc:date>2019-03-12T00:05:38Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with 5505 layout</title>
      <link>https://community.cisco.com/t5/network-security/need-help-with-5505-layout/m-p/2042656#M398017</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not sure I follow you.&lt;/P&gt;&lt;P&gt;You can configure a trunk from the switch to the Asa then do&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/1.2&lt;/P&gt;&lt;P&gt; vlan 2&lt;/P&gt;&lt;P&gt; nameif Insidelan2&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.2.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 07 Oct 2012 22:13:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-with-5505-layout/m-p/2042656#M398017</guid>
      <dc:creator>Stuart Gall</dc:creator>
      <dc:date>2012-10-07T22:13:44Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with 5505 layout</title>
      <link>https://community.cisco.com/t5/network-security/need-help-with-5505-layout/m-p/2042657#M398018</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Perhaps I can make this more clear.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the best way of getting to the Asa from the 3560.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are thoughts from my experience.  And also my Asa dosent have trunking in this iOS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Create a separate vlan between the Asa and 3560 to carry all vlan traffic to Asa.( which I believe I tested to work once). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2( I don't think this works but someone told me it would) is leave the Asa how it is (inside if 192.168.1.1 vlan 1. Then on 3560 set port connecting to Asa as routed port with 192.168.1.2/24 and route to Asa. But it dosent make sense to have the same subnet on both sides of a router??? Right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 07 Oct 2012 22:44:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-with-5505-layout/m-p/2042657#M398018</guid>
      <dc:creator>Joe Lentine</dc:creator>
      <dc:date>2012-10-07T22:44:15Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with 5505 layout</title>
      <link>https://community.cisco.com/t5/network-security/need-help-with-5505-layout/m-p/2042658#M398019</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;With a base license you can have two VLANS; more if you do not route them with &lt;/P&gt;&lt;P&gt;  no forward interface vlan number&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are routing why not just re-ip the link with the asa.&lt;/P&gt;&lt;P&gt;A router will get confused with two interfaces on different subsets with the same ip range.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 07 Oct 2012 22:56:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-with-5505-layout/m-p/2042658#M398019</guid>
      <dc:creator>Stuart Gall</dc:creator>
      <dc:date>2012-10-07T22:56:17Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with 5505 layout</title>
      <link>https://community.cisco.com/t5/network-security/need-help-with-5505-layout/m-p/2042659#M398020</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's what I was thinking...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So for instance. If I have all my internal vlans on the 3560 and then say for the sake of argument make vlan 80 from the 3560 to the Asa both regular access ports, everything should work fine as long as the Asa knows about the vlans on the 3560...&lt;/P&gt;&lt;P&gt;Does this sound right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 07 Oct 2012 23:07:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-with-5505-layout/m-p/2042659#M398020</guid>
      <dc:creator>Joe Lentine</dc:creator>
      <dc:date>2012-10-07T23:07:27Z</dc:date>
    </item>
    <item>
      <title>Need help with 5505 layout</title>
      <link>https://community.cisco.com/t5/network-security/need-help-with-5505-layout/m-p/2042660#M398021</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hello Joe,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since you have a Layer 3 switch, I would suggest to go ahead and configure all your user vlans on 3560 and a default route from 3560 towards ASA using another vlan access port as you said, then static route on ASA towards you internal Vlan pointing back to your switch. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you do not want the internal Vlan to talk each other, you can use ACL or PBR to accomplish that..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Harish.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Oct 2012 10:06:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-with-5505-layout/m-p/2042660#M398021</guid>
      <dc:creator>Harish Balakrishnan</dc:creator>
      <dc:date>2012-10-08T10:06:08Z</dc:date>
    </item>
  </channel>
</rss>

