<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic asa 5520 sub interface issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5520-sub-interface-issue/m-p/1511100#M658866</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;My ASA 5520 is version 8.2(1).&lt;/P&gt;&lt;P&gt;I configured two subinterfaces:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/3.1&lt;BR /&gt; vlan 272&lt;BR /&gt; nameif WN&lt;BR /&gt; security-level 50&lt;BR /&gt; ip address 10.227.2.254 255.255.255.0 &lt;BR /&gt; ospf cost 10&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/3.2&lt;BR /&gt; vlan 275&lt;BR /&gt; nameif WN275&lt;BR /&gt; security-level 50&lt;BR /&gt; ip address 10.227.5.254 255.255.255.0 &lt;BR /&gt; ospf cost 10&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Users in vlan 272 work fine, but users in vlan 275 can't even ping the gateway 10.227.5.254.&lt;/P&gt;&lt;P&gt;I can't find anything wrong. Only one strange thing I noticed when I do a "sh int ip bri" is the METHOD is different, see below. For Gi0/3.2 it is "manual", rather than "config".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;GigabitEthernet0/3.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.227.2.254&amp;nbsp;&amp;nbsp;&amp;nbsp; YES CONFIG up&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&amp;nbsp; &lt;BR /&gt;GigabitEthernet0/3.2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.227.5.254&amp;nbsp;&amp;nbsp;&amp;nbsp; YES manual up&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess if I can get that "manual" changed to "config", I will have a better chance to get vlan275 to work.&lt;/P&gt;&lt;P&gt;How can I do that? Why it is "manual"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks heaps.&lt;/P&gt;&lt;P&gt;Adam&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 18:32:41 GMT</pubDate>
    <dc:creator>Adamzhang</dc:creator>
    <dc:date>2019-03-11T18:32:41Z</dc:date>
    <item>
      <title>asa 5520 sub interface issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-sub-interface-issue/m-p/1511100#M658866</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;My ASA 5520 is version 8.2(1).&lt;/P&gt;&lt;P&gt;I configured two subinterfaces:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/3.1&lt;BR /&gt; vlan 272&lt;BR /&gt; nameif WN&lt;BR /&gt; security-level 50&lt;BR /&gt; ip address 10.227.2.254 255.255.255.0 &lt;BR /&gt; ospf cost 10&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/3.2&lt;BR /&gt; vlan 275&lt;BR /&gt; nameif WN275&lt;BR /&gt; security-level 50&lt;BR /&gt; ip address 10.227.5.254 255.255.255.0 &lt;BR /&gt; ospf cost 10&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Users in vlan 272 work fine, but users in vlan 275 can't even ping the gateway 10.227.5.254.&lt;/P&gt;&lt;P&gt;I can't find anything wrong. Only one strange thing I noticed when I do a "sh int ip bri" is the METHOD is different, see below. For Gi0/3.2 it is "manual", rather than "config".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;GigabitEthernet0/3.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.227.2.254&amp;nbsp;&amp;nbsp;&amp;nbsp; YES CONFIG up&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&amp;nbsp; &lt;BR /&gt;GigabitEthernet0/3.2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.227.5.254&amp;nbsp;&amp;nbsp;&amp;nbsp; YES manual up&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess if I can get that "manual" changed to "config", I will have a better chance to get vlan275 to work.&lt;/P&gt;&lt;P&gt;How can I do that? Why it is "manual"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks heaps.&lt;/P&gt;&lt;P&gt;Adam&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:32:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-sub-interface-issue/m-p/1511100#M658866</guid>
      <dc:creator>Adamzhang</dc:creator>
      <dc:date>2019-03-11T18:32:41Z</dc:date>
    </item>
    <item>
      <title>Re: asa 5520 sub interface issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-sub-interface-issue/m-p/1511101#M658867</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The switch port that connects to the ASA interface gig0/3, I believe is a trunk port (dot1q), and please make sure that you allow VLAN 275 in that trunk port, and you also have VLAN 275 in your vlan database.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would also like to find out if there is any ICMP policy configured on the ASA that might be blocking ping. Pls check "sh run icmp" output.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Aug 2010 08:50:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-sub-interface-issue/m-p/1511101#M658867</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-08-31T08:50:23Z</dc:date>
    </item>
    <item>
      <title>Re: asa 5520 sub interface issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-sub-interface-issue/m-p/1511102#M658868</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the native vlan on that trunk? If the native vlan is 275, then&lt;/P&gt;&lt;P&gt;change the native vlan to something that is not used in the network (say&lt;/P&gt;&lt;P&gt;900). Since there is no native vlan concept in the firewall subinterface, it&lt;/P&gt;&lt;P&gt;will expect all packets to be tagged for the subinterfaces. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Aug 2010 13:26:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-sub-interface-issue/m-p/1511102#M658868</guid>
      <dc:creator>Nagaraja Thanthry</dc:creator>
      <dc:date>2010-08-31T13:26:52Z</dc:date>
    </item>
    <item>
      <title>Re: asa 5520 sub interface issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-sub-interface-issue/m-p/1511103#M658869</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"Switchport trunk allowed vlan add 275" fixed the problem.&lt;/P&gt;&lt;P&gt;Thanks a lot Halijenn.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Adam&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Sep 2010 02:14:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-sub-interface-issue/m-p/1511103#M658869</guid>
      <dc:creator>Adamzhang</dc:creator>
      <dc:date>2010-09-01T02:14:22Z</dc:date>
    </item>
    <item>
      <title>Re: asa 5520 sub interface issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-sub-interface-issue/m-p/1511104#M658870</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;With regards to the "CONFIG" and "manual" keywords,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;GigabitEthernet0/3.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.227.2.254&amp;nbsp;&amp;nbsp;&amp;nbsp; YES CONFIG up&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&amp;nbsp; &lt;BR /&gt;GigabitEthernet0/3.2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.227.5.254&amp;nbsp;&amp;nbsp;&amp;nbsp; YES manual up&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CONFIG indicates that the IP address for GigabitEthernet0/3.1 was loaded from the startup config.&amp;nbsp; Manual indicates that the device has not been reloaded since the IP address was assigned to GigabitEthernet0/3.2.&amp;nbsp; The same interface will display CONFIG once the device is reloaded.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/s3.html#wp1464786"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/s3.html#wp1464786&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Sep 2010 02:48:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-sub-interface-issue/m-p/1511104#M658870</guid>
      <dc:creator>Allen P Chen</dc:creator>
      <dc:date>2010-09-01T02:48:07Z</dc:date>
    </item>
    <item>
      <title>Re: asa 5520 sub interface issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-sub-interface-issue/m-p/1511105#M658871</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Allen, &lt;/P&gt;&lt;P&gt;Thanks for explaining. That is very good to know. &lt;/P&gt;&lt;P&gt;Adam&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Sep 2010 02:53:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-sub-interface-issue/m-p/1511105#M658871</guid>
      <dc:creator>Adamzhang</dc:creator>
      <dc:date>2010-09-01T02:53:22Z</dc:date>
    </item>
  </channel>
</rss>

