<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA VLAN subinterfaces in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-vlan-subinterfaces/m-p/949038#M419895</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you use subinterfaces, you typically do not also want the physical interface to pass traffic, because the physical interface passes untagged packets. Because the physical interface must be enabled for the subinterface to pass traffic, ensure that the physical interface does not pass traffic by leaving out the nameif command. If you want to let the physical interface pass untagged packets, you can configure the nameif command as usual. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The configuration of security levels on sub-interface is the same as physical interfaces. Here's a document on security levels.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://cisco.com/en/US/docs/security/asa/asa70/configuration/guide/intparam.html" target="_blank"&gt;http://cisco.com/en/US/docs/security/asa/asa70/configuration/guide/intparam.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 14 Mar 2008 13:43:48 GMT</pubDate>
    <dc:creator>Collin Clark</dc:creator>
    <dc:date>2008-03-14T13:43:48Z</dc:date>
    <item>
      <title>ASA VLAN subinterfaces</title>
      <link>https://community.cisco.com/t5/network-security/asa-vlan-subinterfaces/m-p/949037#M419894</link>
      <description>&lt;P&gt;When I configure subinterfaces on an ASA, how does the security level of the physical interface interact with the security levels of the subinterfaces?  Can I make the subinterfaces security levels different from the security level of the physical interface and how is this handled?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TIA&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 09:56:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vlan-subinterfaces/m-p/949037#M419894</guid>
      <dc:creator>f00f1ter</dc:creator>
      <dc:date>2020-02-21T09:56:25Z</dc:date>
    </item>
    <item>
      <title>Re: ASA VLAN subinterfaces</title>
      <link>https://community.cisco.com/t5/network-security/asa-vlan-subinterfaces/m-p/949038#M419895</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you use subinterfaces, you typically do not also want the physical interface to pass traffic, because the physical interface passes untagged packets. Because the physical interface must be enabled for the subinterface to pass traffic, ensure that the physical interface does not pass traffic by leaving out the nameif command. If you want to let the physical interface pass untagged packets, you can configure the nameif command as usual. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The configuration of security levels on sub-interface is the same as physical interfaces. Here's a document on security levels.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://cisco.com/en/US/docs/security/asa/asa70/configuration/guide/intparam.html" target="_blank"&gt;http://cisco.com/en/US/docs/security/asa/asa70/configuration/guide/intparam.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Mar 2008 13:43:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vlan-subinterfaces/m-p/949038#M419895</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2008-03-14T13:43:48Z</dc:date>
    </item>
  </channel>
</rss>

