<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Configure sub-interfaces in Cisco ASA 5520 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/configure-sub-interfaces-in-cisco-asa-5520/m-p/1944278#M436031</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Yolande,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is one example below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; speed 100&lt;/P&gt;&lt;P&gt; duplex full&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0.1&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;vlan 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt; nameif management&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.10.10.1 255.255.255.252 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this answers your question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Rizwan Rafeek&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Message was edited by: Rizwan Mohamed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 24 May 2012 13:17:08 GMT</pubDate>
    <dc:creator>rizwanr74</dc:creator>
    <dc:date>2012-05-24T13:17:08Z</dc:date>
    <item>
      <title>Configure sub-interfaces in Cisco ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/configure-sub-interfaces-in-cisco-asa-5520/m-p/1944277#M436030</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a cisco ASA 5520 that i'm configuring.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the actual Firewall (with is a linux server), we have the outside interface eth0 with has a public IP and other sub-interfaces (eth0.1; eth0.2,...) with others publics IPs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'd like to know how I can configure it in an ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:11:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configure-sub-interfaces-in-cisco-asa-5520/m-p/1944277#M436030</guid>
      <dc:creator>yolande_n</dc:creator>
      <dc:date>2019-03-11T23:11:03Z</dc:date>
    </item>
    <item>
      <title>Re: Configure sub-interfaces in Cisco ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/configure-sub-interfaces-in-cisco-asa-5520/m-p/1944278#M436031</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Yolande,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is one example below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; speed 100&lt;/P&gt;&lt;P&gt; duplex full&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0.1&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;vlan 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt; nameif management&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.10.10.1 255.255.255.252 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this answers your question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Rizwan Rafeek&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Message was edited by: Rizwan Mohamed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 May 2012 13:17:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configure-sub-interfaces-in-cisco-asa-5520/m-p/1944278#M436031</guid>
      <dc:creator>rizwanr74</dc:creator>
      <dc:date>2012-05-24T13:17:08Z</dc:date>
    </item>
    <item>
      <title>Re: Configure sub-interfaces in Cisco ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/configure-sub-interfaces-in-cisco-asa-5520/m-p/1944279#M436032</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi rizwanr74,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in your configuration, you add vlan1. should I always put the vlan?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have about 10 sub interfaces to configure with the ASA; i am wondering if i should create 10 vlans&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 May 2012 13:23:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configure-sub-interfaces-in-cisco-asa-5520/m-p/1944279#M436032</guid>
      <dc:creator>yolande_n</dc:creator>
      <dc:date>2012-05-24T13:23:11Z</dc:date>
    </item>
    <item>
      <title>Re: Configure sub-interfaces in Cisco ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/configure-sub-interfaces-in-cisco-asa-5520/m-p/1944280#M436033</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"in your configuration, you add vlan1. should I always put the vlan?"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, you must have a vlan number and ASA's port in the example it is "interface Ethernet0/0" will be connected a trunk port on to a switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With layer2 vlan number, your internal switch will know for which vlan it must forward to packet to.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"I have about 10 sub interfaces to configure with the ASA; i am wondering if i should create 10 vlans"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Natually you will have to create ten subinerfaces with layer2 vlan number.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that answers your question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Rizwan Rafeek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 May 2012 13:32:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configure-sub-interfaces-in-cisco-asa-5520/m-p/1944280#M436033</guid>
      <dc:creator>rizwanr74</dc:creator>
      <dc:date>2012-05-24T13:32:14Z</dc:date>
    </item>
    <item>
      <title>Re: Configure sub-interfaces in Cisco ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/configure-sub-interfaces-in-cisco-asa-5520/m-p/1944281#M436036</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if i resume, i should just create a layer 2 vlan and then my 10 subinterfaces with be linked to the vlan number?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 May 2012 13:39:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configure-sub-interfaces-in-cisco-asa-5520/m-p/1944281#M436036</guid>
      <dc:creator>yolande_n</dc:creator>
      <dc:date>2012-05-24T13:39:16Z</dc:date>
    </item>
    <item>
      <title>Configure sub-interfaces in Cisco ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/configure-sub-interfaces-in-cisco-asa-5520/m-p/1944282#M436037</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"if i resume, i should just create a layer 2 vlan and then my 10 subinterfaces with be linked to the vlan number?"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You do not create the layer2 vlan numbers sperately on the ASA, but rather you assing a subinterface itself to a layer2 vlan number (as shown below), by doing so your trunk port on your switch will know for switch layer2 vlan a given packet is coming on the trunk port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet&lt;STRONG&gt;0/0.200&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;vlan 200&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt; nameif &lt;STRONG&gt;inside&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address &lt;STRONG&gt;10.10.10.1 255.255.255.252 &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet&lt;STRONG&gt;0/1.300&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;vlan 300&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt; nameif &lt;STRONG&gt;management&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address &lt;STRONG&gt;10.30.30.1 255.255.255.252 &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Hope this answers your question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Rizwan Rafeek&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate helful post.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 May 2012 14:14:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configure-sub-interfaces-in-cisco-asa-5520/m-p/1944282#M436037</guid>
      <dc:creator>rizwanr74</dc:creator>
      <dc:date>2012-05-24T14:14:55Z</dc:date>
    </item>
    <item>
      <title>Configure sub-interfaces in Cisco ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/configure-sub-interfaces-in-cisco-asa-5520/m-p/1944283#M436039</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for your answer but my concern if that those vlan (200, 300 on your example) are there also in my lan? because on my lan, i have some Vlan which are not on my actual firewall.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 May 2012 07:22:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configure-sub-interfaces-in-cisco-asa-5520/m-p/1944283#M436039</guid>
      <dc:creator>yolande_n</dc:creator>
      <dc:date>2012-05-25T07:22:07Z</dc:date>
    </item>
    <item>
      <title>Re: Configure sub-interfaces in Cisco ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/configure-sub-interfaces-in-cisco-asa-5520/m-p/1944284#M436040</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You would want to create a vlan in the Firewall at first place, only if you have those vlan locally exists on your LAN or WAN for peering with given segments.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you do create a vlan just only on your Firewall without that particular vlan exists on your LAN or WAN, where does the traffic from such vlan can communicate with for peering?&amp;nbsp; Answers is nowhere.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope that answers your question or concern.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Rizwan Rafeek.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate helful post.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 May 2012 15:04:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configure-sub-interfaces-in-cisco-asa-5520/m-p/1944284#M436040</guid>
      <dc:creator>rizwanr74</dc:creator>
      <dc:date>2012-05-25T15:04:40Z</dc:date>
    </item>
    <item>
      <title>Re: Configure sub-interfaces in Cisco ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/configure-sub-interfaces-in-cisco-asa-5520/m-p/3376257#M436043</link>
      <description>&lt;P&gt;no&lt;/P&gt;</description>
      <pubDate>Tue, 01 May 2018 23:10:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configure-sub-interfaces-in-cisco-asa-5520/m-p/3376257#M436043</guid>
      <dc:creator>robertkwilcox1</dc:creator>
      <dc:date>2018-05-01T23:10:06Z</dc:date>
    </item>
    <item>
      <title>Re: Configure sub-interfaces in Cisco ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/configure-sub-interfaces-in-cisco-asa-5520/m-p/3377205#M436045</link>
      <description>Can you share the configuration of the switch port that is connected to the Linux eth0 interface?&lt;BR /&gt;I want to find out if you're using tagged traffic or you have just secondary IP addresses on your Linux interface (same vlan).&lt;BR /&gt;&lt;BR /&gt;Thanks!</description>
      <pubDate>Thu, 03 May 2018 09:00:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configure-sub-interfaces-in-cisco-asa-5520/m-p/3377205#M436045</guid>
      <dc:creator>Florin Barhala</dc:creator>
      <dc:date>2018-05-03T09:00:44Z</dc:date>
    </item>
  </channel>
</rss>

