<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DMZ Sub interfaces into sub interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/dmz-sub-interfaces-into-sub-interface/m-p/2008146#M439878</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P id="3677119" style="border-collapse: collapse; font-size: 12px; list-style-type: none; margin-left: 20px; padding-top: 10px; padding-right: 10px; padding-left: 10px; overflow-x: visible; overflow-y: visible; position: static;"&gt;&amp;gt; Can we break this feature on catalyst switches 2960 or 3560?&lt;/P&gt;&lt;P style="border-collapse: collapse; font-size: 12px; list-style-type: none; margin-left: 20px; padding-top: 10px; padding-right: 10px; padding-left: 10px; overflow-x: visible; overflow-y: visible; position: static;"&gt;You just want to have two IP-networks in one VLAN? If yes, that is possible on Routers and Switches with secondary IP-addresses. But the ASA doesn't support that.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 06 Jul 2012 22:36:20 GMT</pubDate>
    <dc:creator>Karsten Iwen</dc:creator>
    <dc:date>2012-07-06T22:36:20Z</dc:date>
    <item>
      <title>DMZ Sub interfaces into sub interface</title>
      <link>https://community.cisco.com/t5/network-security/dmz-sub-interfaces-into-sub-interface/m-p/2008142#M439874</link>
      <description>&lt;DIV style="border-collapse: collapse; list-style: none; margin: 0px 0px 20px; padding: 2px; overflow: visible; position: relative; zoom: 1; width: 706.3636474609375px;"&gt;&lt;P style="border-collapse: collapse; list-style: none;"&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="border-collapse: collapse; list-style: none;"&gt;We have ASA FW 5010 in our organization and we have 4 DMZ's under the DMZ interface on ASA and all DMZ's are created on sub interfaces and assigned different VLANS on each DMZ's like&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="border-collapse: collapse; list-style: none;"&gt;DMZ-1 = 172.20.1.x - VLAN 1000&lt;/P&gt;&lt;P style="border-collapse: collapse; list-style: none;"&gt;DMZ-2 = 172.20.2.x - VLAN 1200&lt;/P&gt;&lt;P style="border-collapse: collapse; list-style: none;"&gt;DMZ-3 = 172.20.3.x - VLAN 1300&lt;/P&gt;&lt;P style="border-collapse: collapse; list-style: none;"&gt;DMZ-4 = 172.20.4.x - VLAN 1400&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="border-collapse: collapse; list-style: none;"&gt;My question is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="border-collapse: collapse; list-style: none;"&gt;Can we break sub interface (DMZ-4) into again another sub interface and assign another IP address like&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="border-collapse: collapse; list-style: none;"&gt;DMZ-4 = 172.20.4.x&lt;/P&gt;&lt;P style="border-collapse: collapse; list-style: none;"&gt;---------= 172.20.5.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="border-collapse: collapse; list-style: none;"&gt;Means one VLAN has two IP addresses for gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="border-collapse: collapse; list-style: none;"&gt;One thing more how many times we can break one interface into subinterfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="border-collapse: collapse; list-style: none;"&gt;I hope my question is enough for understanding.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="border-collapse: collapse; list-style: none;"&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="border-collapse: collapse; list-style: none;"&gt;Saeed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:27:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-sub-interfaces-into-sub-interface/m-p/2008142#M439874</guid>
      <dc:creator>saeedccie</dc:creator>
      <dc:date>2019-03-11T23:27:25Z</dc:date>
    </item>
    <item>
      <title>DMZ Sub interfaces into sub interface</title>
      <link>https://community.cisco.com/t5/network-security/dmz-sub-interfaces-into-sub-interface/m-p/2008143#M439875</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, this is not a supported feature.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think you can put 250 subinterfaces on a physical interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jul 2012 17:50:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-sub-interfaces-into-sub-interface/m-p/2008143#M439875</guid>
      <dc:creator>deyster94</dc:creator>
      <dc:date>2012-07-06T17:50:33Z</dc:date>
    </item>
    <item>
      <title>DMZ Sub interfaces into sub interface</title>
      <link>https://community.cisco.com/t5/network-security/dmz-sub-interfaces-into-sub-interface/m-p/2008144#M439876</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can we break this feature on catalyst switches 2960 or 3560?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jul 2012 17:53:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-sub-interfaces-into-sub-interface/m-p/2008144#M439876</guid>
      <dc:creator>saeedccie</dc:creator>
      <dc:date>2012-07-06T17:53:50Z</dc:date>
    </item>
    <item>
      <title>DMZ Sub interfaces into sub interface</title>
      <link>https://community.cisco.com/t5/network-security/dmz-sub-interfaces-into-sub-interface/m-p/2008145#M439877</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"Can we break this feature on catalyst switches 2960 or 3560?"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Answer is still no.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that answers your question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Rizwan Rafeek.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jul 2012 18:28:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-sub-interfaces-into-sub-interface/m-p/2008145#M439877</guid>
      <dc:creator>rizwanr74</dc:creator>
      <dc:date>2012-07-06T18:28:02Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ Sub interfaces into sub interface</title>
      <link>https://community.cisco.com/t5/network-security/dmz-sub-interfaces-into-sub-interface/m-p/2008146#M439878</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P id="3677119" style="border-collapse: collapse; font-size: 12px; list-style-type: none; margin-left: 20px; padding-top: 10px; padding-right: 10px; padding-left: 10px; overflow-x: visible; overflow-y: visible; position: static;"&gt;&amp;gt; Can we break this feature on catalyst switches 2960 or 3560?&lt;/P&gt;&lt;P style="border-collapse: collapse; font-size: 12px; list-style-type: none; margin-left: 20px; padding-top: 10px; padding-right: 10px; padding-left: 10px; overflow-x: visible; overflow-y: visible; position: static;"&gt;You just want to have two IP-networks in one VLAN? If yes, that is possible on Routers and Switches with secondary IP-addresses. But the ASA doesn't support that.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jul 2012 22:36:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-sub-interfaces-into-sub-interface/m-p/2008146#M439878</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2012-07-06T22:36:20Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ Sub interfaces into sub interface</title>
      <link>https://community.cisco.com/t5/network-security/dmz-sub-interfaces-into-sub-interface/m-p/2008147#M439879</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Saeed,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can create sub interface for the sub interface... because virtual interfaces can be created on the physical interfaces...... But two ip segments for a single vlan is possible in L3 switches / Routers. I never tried it in firewalls....&lt;/P&gt;&lt;P&gt; Here is the example in L3 switch&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan100&lt;/P&gt;&lt;P&gt; ip address 10.0.0.4 255.255.255.0 secondary&lt;/P&gt;&lt;P&gt; ip address 10.2.2.4 255.255.254.0&lt;/P&gt;&lt;P&gt;no shut&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 07 Jul 2012 18:11:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-sub-interfaces-into-sub-interface/m-p/2008147#M439879</guid>
      <dc:creator>nkarthikeyan</dc:creator>
      <dc:date>2012-07-07T18:11:16Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ Sub interfaces into sub interface</title>
      <link>https://community.cisco.com/t5/network-security/dmz-sub-interfaces-into-sub-interface/m-p/2008148#M439880</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry... Small correction... You cannot create....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 07 Jul 2012 18:11:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-sub-interfaces-into-sub-interface/m-p/2008148#M439880</guid>
      <dc:creator>nkarthikeyan</dc:creator>
      <dc:date>2012-07-07T18:11:41Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ Sub interfaces into sub interface</title>
      <link>https://community.cisco.com/t5/network-security/dmz-sub-interfaces-into-sub-interface/m-p/2008149#M439881</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ASA 5510 supports max of 100 sub interfaces / vlans..... &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 07 Jul 2012 18:21:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-sub-interfaces-into-sub-interface/m-p/2008149#M439881</guid>
      <dc:creator>nkarthikeyan</dc:creator>
      <dc:date>2012-07-07T18:21:10Z</dc:date>
    </item>
  </channel>
</rss>

