<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX 515e, multiple VLAN's on one physical DMZ interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-515e-multiple-vlan-s-on-one-physical-dmz-interface/m-p/317534#M549587</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Creating VLANs on Ethernet1&lt;/P&gt;&lt;P&gt;We want to create one new VLAN interface - VLAN30 and call it DMZ2. Also assign security level 50 to it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Step 1:  Create a Physical Interface:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pix(config)# interface ethernet1 vlan2 physical&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Step 2: Name the Interface and set the Security Level:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pix(config)# nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Step 3:  Assign IP Address to the interface:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pix(config)# ip address inside 192.168.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Step 4:  Create the Logical Interface:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pix(config)# interface ethernet1 vlan30 logical&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Step 5:  Name the Interface and set the Security Level:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pix(config)# nameif vlan30 DMZ2 security50&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Step 6:  Assign IP Address to the interface:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pix(config)# ip address DMZ2 192.168.100.254 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Step7. On Switch , set the port where the physical interface the inside, for trunking ISL or dot1q. place the trunking in the native vlan2 like in step 1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 07 Apr 2005 19:43:15 GMT</pubDate>
    <dc:creator>tonyam98</dc:creator>
    <dc:date>2005-04-07T19:43:15Z</dc:date>
    <item>
      <title>PIX 515e, multiple VLAN's on one physical DMZ interface</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-multiple-vlan-s-on-one-physical-dmz-interface/m-p/317526#M549578</link>
      <description>&lt;P&gt;We are trying to set up multiple VLAN's on one physical DMZ interface on a PIX 515e.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The goal is to have separate logical subnets connected to our one, physical, DMZ interface.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is what I have tried so far without success:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On switch&lt;/P&gt;&lt;P&gt;-created vlan 30&lt;/P&gt;&lt;P&gt;-added switchports fa0/1 to vlan 30&lt;/P&gt;&lt;P&gt;-connected host 192.168.100.1 into fa0/1&lt;/P&gt;&lt;P&gt;-added switchport fa0/24 to to vlan 1, and vlan 30 with multimode&lt;/P&gt;&lt;P&gt;-connected PIX DMZ interface to switchport fa0/24&lt;/P&gt;&lt;P&gt;-connected host 172.16.1.55 to switchport fa0/10 (vlan 1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On PIX:&lt;/P&gt;&lt;P&gt;interface ethernet2 auto&lt;/P&gt;&lt;P&gt;interface ethernet2 vlan30 logical&lt;/P&gt;&lt;P&gt;nameif ethernet2 DMZ security50&lt;/P&gt;&lt;P&gt;nameif vlan30 dmz2 security50&lt;/P&gt;&lt;P&gt;ip address DMZ 172.16.1.254 255.255.255.0&lt;/P&gt;&lt;P&gt;ip address dmz2 192.168.100.254 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Results:&lt;/P&gt;&lt;P&gt;-172.16.1.55 has full connectivity to the PIX and beyond.&lt;/P&gt;&lt;P&gt;-192.168.100.1 cannot ping the PIX at 192.168.100.254 or anything else for that matter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be greatly appreciated.  I also realize that I could buy a four port NIC and use physical interfaces, but I can't get the purchase approved.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:03:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-multiple-vlan-s-on-one-physical-dmz-interface/m-p/317526#M549578</guid>
      <dc:creator>vantagepointisg</dc:creator>
      <dc:date>2020-02-21T08:03:53Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515e, multiple VLAN's on one physical DMZ interface</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-multiple-vlan-s-on-one-physical-dmz-interface/m-p/317527#M549579</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We also are not trunking the VLAN's as we thought that wouldn't be necessary.  We would be happy at this point to get the 192.168.100.1 host to ping the PIX at 192.168.100.254.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Apr 2005 13:53:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-multiple-vlan-s-on-one-physical-dmz-interface/m-p/317527#M549579</guid>
      <dc:creator>vantagepointisg</dc:creator>
      <dc:date>2005-04-07T13:53:48Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515e, multiple VLAN's on one physical DMZ interface</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-multiple-vlan-s-on-one-physical-dmz-interface/m-p/317528#M549580</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try configuring it as a trunk. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Apr 2005 14:08:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-multiple-vlan-s-on-one-physical-dmz-interface/m-p/317528#M549580</guid>
      <dc:creator>mostiguy</dc:creator>
      <dc:date>2005-04-07T14:08:28Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515e, multiple VLAN's on one physical DMZ interface</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-multiple-vlan-s-on-one-physical-dmz-interface/m-p/317529#M549581</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you allowed this on the pix?&lt;/P&gt;&lt;P&gt;icmp permit host 192.168.100.1&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Apr 2005 14:31:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-multiple-vlan-s-on-one-physical-dmz-interface/m-p/317529#M549581</guid>
      <dc:creator>jonathanstevens</dc:creator>
      <dc:date>2005-04-07T14:31:47Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515e, multiple VLAN's on one physical DMZ interface</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-multiple-vlan-s-on-one-physical-dmz-interface/m-p/317530#M549582</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Will a PIX 515e handle ISL trunking?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Apr 2005 15:08:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-multiple-vlan-s-on-one-physical-dmz-interface/m-p/317530#M549582</guid>
      <dc:creator>vantagepointisg</dc:creator>
      <dc:date>2005-04-07T15:08:18Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515e, multiple VLAN's on one physical DMZ interface</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-multiple-vlan-s-on-one-physical-dmz-interface/m-p/317531#M549583</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes all traffic is allowed from this host on this interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Apr 2005 15:09:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-multiple-vlan-s-on-one-physical-dmz-interface/m-p/317531#M549583</guid>
      <dc:creator>vantagepointisg</dc:creator>
      <dc:date>2005-04-07T15:09:34Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515e, multiple VLAN's on one physical DMZ interface</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-multiple-vlan-s-on-one-physical-dmz-interface/m-p/317532#M549584</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I believe PIXs only support dot1q&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Apr 2005 16:26:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-multiple-vlan-s-on-one-physical-dmz-interface/m-p/317532#M549584</guid>
      <dc:creator>jonathanstevens</dc:creator>
      <dc:date>2005-04-07T16:26:56Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515e, multiple VLAN's on one physical DMZ interface</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-multiple-vlan-s-on-one-physical-dmz-interface/m-p/317533#M549585</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's all that I've found too.  I didn't know if they could handle ISL or not.  I will make the uplink port on the switch (fa0/24) a dot1q trunk port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will let you know how it goes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Apr 2005 16:33:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-multiple-vlan-s-on-one-physical-dmz-interface/m-p/317533#M549585</guid>
      <dc:creator>vantagepointisg</dc:creator>
      <dc:date>2005-04-07T16:33:34Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515e, multiple VLAN's on one physical DMZ interface</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-multiple-vlan-s-on-one-physical-dmz-interface/m-p/317534#M549587</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Creating VLANs on Ethernet1&lt;/P&gt;&lt;P&gt;We want to create one new VLAN interface - VLAN30 and call it DMZ2. Also assign security level 50 to it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Step 1:  Create a Physical Interface:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pix(config)# interface ethernet1 vlan2 physical&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Step 2: Name the Interface and set the Security Level:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pix(config)# nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Step 3:  Assign IP Address to the interface:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pix(config)# ip address inside 192.168.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Step 4:  Create the Logical Interface:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pix(config)# interface ethernet1 vlan30 logical&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Step 5:  Name the Interface and set the Security Level:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pix(config)# nameif vlan30 DMZ2 security50&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Step 6:  Assign IP Address to the interface:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pix(config)# ip address DMZ2 192.168.100.254 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Step7. On Switch , set the port where the physical interface the inside, for trunking ISL or dot1q. place the trunking in the native vlan2 like in step 1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Apr 2005 19:43:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-multiple-vlan-s-on-one-physical-dmz-interface/m-p/317534#M549587</guid>
      <dc:creator>tonyam98</dc:creator>
      <dc:date>2005-04-07T19:43:15Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515e, multiple VLAN's on one physical DMZ interface</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-multiple-vlan-s-on-one-physical-dmz-interface/m-p/317535#M549588</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Works like a champ!  I also found this which was helpful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.ciscotaccc.com/security/showcase?case=K10055697" target="_blank"&gt;http://www.ciscotaccc.com/security/showcase?case=K10055697&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Apr 2005 23:38:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-multiple-vlan-s-on-one-physical-dmz-interface/m-p/317535#M549588</guid>
      <dc:creator>vantagepointisg</dc:creator>
      <dc:date>2005-04-07T23:38:40Z</dc:date>
    </item>
  </channel>
</rss>

