<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Pix 535 interface bundling in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-535-interface-bundling/m-p/1367153#M744849</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Exactly.&amp;nbsp; You got it. But, the config looks like this. Pls. leave the main interface blank.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is a sample:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;interface GigabitEthernet0/0&lt;BR /&gt; speed 100&lt;BR /&gt; duplex full&lt;BR /&gt; no nameif&lt;BR /&gt; no security-level&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/0.1&lt;BR /&gt; vlan 10&lt;BR /&gt; nameif dmz1&lt;BR /&gt; security-level 50&lt;BR /&gt; ip address 10.128.0.1 255.255.255.0&lt;BR /&gt;&lt;BR /&gt;interface GigabitEthernet0/0.2&lt;BR /&gt; vlan 20&lt;BR /&gt; nameif dmz2&lt;BR /&gt; security-level 60&lt;BR /&gt; ip address 192.168.0.1 255.255.255.0&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 13 Jan 2010 18:46:10 GMT</pubDate>
    <dc:creator>Kureli Sankar</dc:creator>
    <dc:date>2010-01-13T18:46:10Z</dc:date>
    <item>
      <title>Pix 535 interface bundling</title>
      <link>https://community.cisco.com/t5/network-security/pix-535-interface-bundling/m-p/1367149#M744845</link>
      <description>&lt;P&gt;does anybody know if you can "bundle" gig interfaces on a PIX 535 and then further use the bundled interface as a trunk?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bruce&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:57:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-535-interface-bundling/m-p/1367149#M744845</guid>
      <dc:creator>Bruce Summers</dc:creator>
      <dc:date>2019-03-11T16:57:30Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 535 interface bundling</title>
      <link>https://community.cisco.com/t5/network-security/pix-535-interface-bundling/m-p/1367150#M744846</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;bruce.summers wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;does anybody know if you can "bundle" gig interfaces on a PIX 535 and then further use the bundled interface as a trunk?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bruce&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bruce&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No the pix firewalls do not support etherchannel ie. bundling multiple physical links into one logcial link.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can however run a physical interface to a switch and configure the link as an 802.1Q trunk on the switch end and then have subinterfaces on the pix firewall but you probably know this already.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jan 2010 17:44:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-535-interface-bundling/m-p/1367150#M744846</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2010-01-13T17:44:43Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 535 interface bundling</title>
      <link>https://community.cisco.com/t5/network-security/pix-535-interface-bundling/m-p/1367151#M744847</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;well...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am learning quickly about the subinterfaces...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so, based on what you're saying, i could do the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;int g1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;subint g1.35&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; vlan 1234&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; vlan 3456&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;connect g1 to switch A 1/0/1 and configure switch A's uplink interface as an 802.1q trunk allowing vlan1234 and vlan3456&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thats what you're referring to, correct?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jan 2010 17:56:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-535-interface-bundling/m-p/1367151#M744847</guid>
      <dc:creator>Bruce Summers</dc:creator>
      <dc:date>2010-01-13T17:56:40Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 535 interface bundling</title>
      <link>https://community.cisco.com/t5/network-security/pix-535-interface-bundling/m-p/1367152#M744848</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I just tested that out...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, that makes sense now..i can trunk vlans up to the switch using a single physical interface and configure sub-interfaces to be allocated to my security context(s) to function as vlan interfaces...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but, the best i'm going to be able to do it looks like, is use the redundant interface option...this will give me some "failover" capability, but not provide the 2 gig throughput i was hoping to get...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;does that pretty much sum it up...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, i've heard ver 8.0 is "unstable" any thoughts on that...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;bruce&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jan 2010 18:08:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-535-interface-bundling/m-p/1367152#M744848</guid>
      <dc:creator>Bruce Summers</dc:creator>
      <dc:date>2010-01-13T18:08:29Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 535 interface bundling</title>
      <link>https://community.cisco.com/t5/network-security/pix-535-interface-bundling/m-p/1367153#M744849</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Exactly.&amp;nbsp; You got it. But, the config looks like this. Pls. leave the main interface blank.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is a sample:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;interface GigabitEthernet0/0&lt;BR /&gt; speed 100&lt;BR /&gt; duplex full&lt;BR /&gt; no nameif&lt;BR /&gt; no security-level&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/0.1&lt;BR /&gt; vlan 10&lt;BR /&gt; nameif dmz1&lt;BR /&gt; security-level 50&lt;BR /&gt; ip address 10.128.0.1 255.255.255.0&lt;BR /&gt;&lt;BR /&gt;interface GigabitEthernet0/0.2&lt;BR /&gt; vlan 20&lt;BR /&gt; nameif dmz2&lt;BR /&gt; security-level 60&lt;BR /&gt; ip address 192.168.0.1 255.255.255.0&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jan 2010 18:46:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-535-interface-bundling/m-p/1367153#M744849</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-01-13T18:46:10Z</dc:date>
    </item>
    <item>
      <title>Re: Pix 535 interface bundling</title>
      <link>https://community.cisco.com/t5/network-security/pix-535-interface-bundling/m-p/1367154#M744850</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;bruce.summers wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just tested that out...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, that makes sense now..i can trunk vlans up to the switch using a single physical interface and configure sub-interfaces to be allocated to my security context(s) to function as vlan interfaces...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but, the best i'm going to be able to do it looks like, is use the redundant interface option...this will give me some "failover" capability, but not provide the 2 gig throughput i was hoping to get...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;does that pretty much sum it up...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, i've heard ver 8.0 is "unstable" any thoughts on that...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;bruce&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bruce&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is the tradeoff with using subinterfaces i'm afraid in that you now have multiple vlans sharing the 1Gbps bandwidth of the physical interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not had any experience with v8.x as yet so can't really comment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jan 2010 18:47:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-535-interface-bundling/m-p/1367154#M744850</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2010-01-13T18:47:09Z</dc:date>
    </item>
  </channel>
</rss>

