<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 55xx - Layer 2 vs Layer 3 Best Practice? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-55xx-layer-2-vs-layer-3-best-practice/m-p/1487345#M726045</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I guess I should have been a little more clear - should the switches be running Layer 2 or Layer 3.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Option 1 - Layer 2 switch, requires trunking and static route statements on the firewall. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Option 2 - Layer 3 switch, use VLAN subinterfaces, trunking.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think both require static NAT statements to allow the VLANs with same security level to communicate.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 31 May 2010 17:30:50 GMT</pubDate>
    <dc:creator>sdhill</dc:creator>
    <dc:date>2010-05-31T17:30:50Z</dc:date>
    <item>
      <title>ASA 55xx - Layer 2 vs Layer 3 Best Practice?</title>
      <link>https://community.cisco.com/t5/network-security/asa-55xx-layer-2-vs-layer-3-best-practice/m-p/1487343#M726043</link>
      <description>&lt;P&gt;Depending on the person at TAC some recommend using only layer 2 and while others suggest using layer 3 when using the firewall in routed mode and not utilizing a router. So what does everyone think? Keep in mind the possibility of using VPN access due to hairpin issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Should you use a layer 3 switch, define the VLANS, turn on ip routing, and trunk to the firewall interface with VLAN subinterfaces? or&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Use a layer 2 switch, define the VLANS, use ip default-gateway, and define static routes on the firewall?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:52:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-55xx-layer-2-vs-layer-3-best-practice/m-p/1487343#M726043</guid>
      <dc:creator>sdhill</dc:creator>
      <dc:date>2019-03-11T17:52:37Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 55xx - Layer 2 vs Layer 3 Best Practice?</title>
      <link>https://community.cisco.com/t5/network-security/asa-55xx-layer-2-vs-layer-3-best-practice/m-p/1487344#M726044</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Since you would like to terminate VPN on the ASA, then you would need to go with Layer 3 (routed firewall), because Layer 2 (transparent firewall) does not support VPN termination.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are a list of things that are not supported on Layer 2 firewall for your reference:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/fwmode.html#wp1222823"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/fwmode.html#wp1222823&lt;/A&gt;&lt;/P&gt;&lt;P&gt;(&lt;SPAN class="content"&gt;Table 4-1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Unsupported Features in Transparent Mode)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The actual doc also explains both firewall as a routed and transparent firewall for your reference:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/fwmode.html"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/fwmode.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 May 2010 10:18:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-55xx-layer-2-vs-layer-3-best-practice/m-p/1487344#M726044</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-05-31T10:18:53Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 55xx - Layer 2 vs Layer 3 Best Practice?</title>
      <link>https://community.cisco.com/t5/network-security/asa-55xx-layer-2-vs-layer-3-best-practice/m-p/1487345#M726045</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I guess I should have been a little more clear - should the switches be running Layer 2 or Layer 3.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Option 1 - Layer 2 switch, requires trunking and static route statements on the firewall. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Option 2 - Layer 3 switch, use VLAN subinterfaces, trunking.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think both require static NAT statements to allow the VLANs with same security level to communicate.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 May 2010 17:30:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-55xx-layer-2-vs-layer-3-best-practice/m-p/1487345#M726045</guid>
      <dc:creator>sdhill</dc:creator>
      <dc:date>2010-05-31T17:30:50Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 55xx - Layer 2 vs Layer 3 Best Practice?</title>
      <link>https://community.cisco.com/t5/network-security/asa-55xx-layer-2-vs-layer-3-best-practice/m-p/1487346#M726046</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The fact that you use L2 or L3 switches behind the ASA, it will just change how the ASA look at this devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example,&lt;/P&gt;&lt;P&gt;If you configure the switches at L2, the ASA will look at the switches as regular L2 switches and will share a subnet with the next L3 device on the path to the inside.&lt;/P&gt;&lt;P&gt;If you configure the switches at L3, the ASA will look at those switches as routers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which are the benefits or disadvantages of one solution over the other depends on your entire topology (hard to tell without knowing the layout).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you can post a simple diagram with what you're planning to do, I think you'll get more help here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 May 2010 17:36:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-55xx-layer-2-vs-layer-3-best-practice/m-p/1487346#M726046</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-05-31T17:36:07Z</dc:date>
    </item>
  </channel>
</rss>

