<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic You can associate VLANs in in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-ips-inline-in-bridge-mode-on-a-trunked-interface/m-p/2439913#M45585</link>
    <description>&lt;P&gt;You can associate VLANs in pairs on a physical interface. This is known as inline VLAN pair mode. Packets received on one of the paired VLANs are analyzed and then forwarded to the other VLAN in the pair. but the ASA IPS modules (ASA&amp;nbsp;5500&amp;nbsp;AIP&amp;nbsp;SSM, ASA&amp;nbsp;5500-X&amp;nbsp;IPS&amp;nbsp;SSP, and ASA&amp;nbsp;5585-X&amp;nbsp;IPS&amp;nbsp;SSP) do not support inline VLAN pairs. For more information you can check the following configuration guide.&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/ips/7-1/configuration/guide/cli/cliguide71/cli_interfaces.html&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 06 May 2014 16:46:23 GMT</pubDate>
    <dc:creator>Ravi Singh</dc:creator>
    <dc:date>2014-05-06T16:46:23Z</dc:date>
    <item>
      <title>Cisco ASA IPS inline in bridge mode on a trunked interface</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ips-inline-in-bridge-mode-on-a-trunked-interface/m-p/2439912#M45583</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm trying to figure out how to deploy a Cisco ASA 5512-X IPS inline in bridge mode on an ethernet trunked interface.&lt;/P&gt;&lt;P&gt;switch1--------------vlan10,20----------------ASA IPS--------------vlan10,20----------------switch2&lt;/P&gt;&lt;P&gt;I basically want to drop the IPS inline without changing the existing switch configuration. Its works fine on a non trunked interface but when I configure it similar to the config below I hit the issue that I cant assign 2 separate interfaces to the same VLAN. The exact error is as follows&lt;/P&gt;&lt;P&gt;ERROR: VLAN 10 has been assigned to another interface.&lt;/P&gt;&lt;P&gt;This is such a common scenario I cant imagine there isnt a solution but I cant find one.&amp;nbsp; Does anyone know ?&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;interface Ethernet0/2.10&lt;BR /&gt;vlan 10&lt;BR /&gt;nameif INSIDETEN&lt;BR /&gt;security-level 100&lt;BR /&gt;bridge-group 10&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2.20&lt;BR /&gt;vlan 20&lt;BR /&gt;nameif INSIDETWENTY&lt;BR /&gt;security-level 100&lt;BR /&gt;bridge-group 20&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3.10&lt;BR /&gt;vlan 10&lt;BR /&gt;nameif OUTSIDETEN&lt;BR /&gt;security-level 0&lt;BR /&gt;bridge-group 10&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3.20&lt;BR /&gt;vlan 20&lt;BR /&gt;nameif OUTSIDETWENTY&lt;BR /&gt;security-level 0&lt;BR /&gt;bridge-group 20&lt;BR /&gt;!&lt;BR /&gt;interface BVI10&lt;BR /&gt;ip address x.x.x.x y.y.y.y&lt;/P&gt;&lt;P&gt;interface BVI20&lt;BR /&gt;ip address x.x.x.x y.y.y.y&lt;/P&gt;&lt;P&gt;It doesn't work, I can't configure the VLANs on two different interfaces.&lt;/P&gt;&lt;P&gt;ASA(config-subif)# vlan 10&lt;BR /&gt;ERROR: VLAN 10 has been assigned to another interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 00:20:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ips-inline-in-bridge-mode-on-a-trunked-interface/m-p/2439912#M45583</guid>
      <dc:creator>hancorp</dc:creator>
      <dc:date>2019-03-26T00:20:55Z</dc:date>
    </item>
    <item>
      <title>You can associate VLANs in</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ips-inline-in-bridge-mode-on-a-trunked-interface/m-p/2439913#M45585</link>
      <description>&lt;P&gt;You can associate VLANs in pairs on a physical interface. This is known as inline VLAN pair mode. Packets received on one of the paired VLANs are analyzed and then forwarded to the other VLAN in the pair. but the ASA IPS modules (ASA&amp;nbsp;5500&amp;nbsp;AIP&amp;nbsp;SSM, ASA&amp;nbsp;5500-X&amp;nbsp;IPS&amp;nbsp;SSP, and ASA&amp;nbsp;5585-X&amp;nbsp;IPS&amp;nbsp;SSP) do not support inline VLAN pairs. For more information you can check the following configuration guide.&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/ips/7-1/configuration/guide/cli/cliguide71/cli_interfaces.html&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 May 2014 16:46:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ips-inline-in-bridge-mode-on-a-trunked-interface/m-p/2439913#M45585</guid>
      <dc:creator>Ravi Singh</dc:creator>
      <dc:date>2014-05-06T16:46:23Z</dc:date>
    </item>
  </channel>
</rss>

