<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Multiple VLANs behind single firewall segment? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/multiple-vlans-behind-single-firewall-segment/m-p/1811577#M459979</link>
    <description>&lt;P&gt;Here is what I need to do.&amp;nbsp; I need to create a firewalled segment that not only separates hosts from general population, but also from each other.&amp;nbsp; The solitary confinement of firewalled segments.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know that I could create a bunch of sub-interfaces, one for each host or group that needs to be isolated, but I'd really rather not have to do that if possible.&amp;nbsp; 1) It could become a management nightmare between ACLs and sub-interfaces and 2) it's a waste of IP addresses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any way that I can create a bunch of separate VLANs behind the firewall and have them all terminate at the firewall, using a single firewall IP address for the gateway?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind of like this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="1" cellpadding="3" cellspacing="0" class="jiveBorder" style="width: 100%; border: 1px solid #000000;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;VLAN 1 - hosts 1.1.1.5 and 1.1.1.6&lt;/TD&gt;&lt;TD&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;VLAN 2 - hosts 1.1.1.7&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;Firewall DMZ Interface - 1.1.1.1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;VLAN 3 - hosts 1.1.1.8 and 1.1.1.9&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This way, the hosts are isolated and can't talk to each other unless they're on the same VLAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, 1) does this make sense? and 2) is it possible?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm working with an ASA 5510 running 8.2.4(4).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jason&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 22:24:52 GMT</pubDate>
    <dc:creator>jason.williams</dc:creator>
    <dc:date>2019-03-11T22:24:52Z</dc:date>
    <item>
      <title>Multiple VLANs behind single firewall segment?</title>
      <link>https://community.cisco.com/t5/network-security/multiple-vlans-behind-single-firewall-segment/m-p/1811577#M459979</link>
      <description>&lt;P&gt;Here is what I need to do.&amp;nbsp; I need to create a firewalled segment that not only separates hosts from general population, but also from each other.&amp;nbsp; The solitary confinement of firewalled segments.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know that I could create a bunch of sub-interfaces, one for each host or group that needs to be isolated, but I'd really rather not have to do that if possible.&amp;nbsp; 1) It could become a management nightmare between ACLs and sub-interfaces and 2) it's a waste of IP addresses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any way that I can create a bunch of separate VLANs behind the firewall and have them all terminate at the firewall, using a single firewall IP address for the gateway?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind of like this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="1" cellpadding="3" cellspacing="0" class="jiveBorder" style="width: 100%; border: 1px solid #000000;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;VLAN 1 - hosts 1.1.1.5 and 1.1.1.6&lt;/TD&gt;&lt;TD&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;VLAN 2 - hosts 1.1.1.7&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;Firewall DMZ Interface - 1.1.1.1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;VLAN 3 - hosts 1.1.1.8 and 1.1.1.9&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This way, the hosts are isolated and can't talk to each other unless they're on the same VLAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, 1) does this make sense? and 2) is it possible?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm working with an ASA 5510 running 8.2.4(4).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jason&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:24:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-vlans-behind-single-firewall-segment/m-p/1811577#M459979</guid>
      <dc:creator>jason.williams</dc:creator>
      <dc:date>2019-03-11T22:24:52Z</dc:date>
    </item>
    <item>
      <title>Multiple VLANs behind single firewall segment?</title>
      <link>https://community.cisco.com/t5/network-security/multiple-vlans-behind-single-firewall-segment/m-p/1811578#M459980</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please read this thread at below link, it was very much similar implementation was done.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/message/3546019#3546019"&gt;https://supportforums.cisco.com/message/3546019#3546019&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Rizwan Rafeek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Feb 2012 20:42:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-vlans-behind-single-firewall-segment/m-p/1811578#M459980</guid>
      <dc:creator>rizwanr74</dc:creator>
      <dc:date>2012-02-06T20:42:00Z</dc:date>
    </item>
  </channel>
</rss>

