<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security zone across two physical interfaces in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/security-zone-across-two-physical-interfaces/m-p/1431313#M746393</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Federico,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ASA-5520 interfaces are G0/0 and G1/0. (Not G0/0 and G0/1)&lt;/P&gt;&lt;P&gt;G0/0 is build into the ASA&lt;/P&gt;&lt;P&gt;G1/0 is on the 4-port module&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Doesyour answer still apply?&lt;/P&gt;&lt;P&gt;Tks&lt;/P&gt;&lt;P&gt;Frank&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 02 Jun 2010 15:36:17 GMT</pubDate>
    <dc:creator>fsebera</dc:creator>
    <dc:date>2010-06-02T15:36:17Z</dc:date>
    <item>
      <title>Security zone across two physical interfaces</title>
      <link>https://community.cisco.com/t5/network-security/security-zone-across-two-physical-interfaces/m-p/1431311#M746375</link>
      <description>&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-bidi-font-family: Arial;"&gt;I have an ASA-5520 running IOS 8-0-4(7).&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-bidi-font-family: Arial;"&gt;I have 24MB flash and 80MB DRAM.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-bidi-font-family: Arial;"&gt;I want to install a 4-port GE SSM module and interconnect two (2) different Cisco 3750 switches as such:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt;"&gt;ASA-5520-1 -- g0/0 ------ c3750-A -- g1/0/1&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt;"&gt;ASA-5520-1 -- g1/0 ------ c3750-B -- g1/0/2&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: black; font-size: 12pt;"&gt;interface GigabitEthernet0/0&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: black; font-size: 12pt;"&gt;Description Built-in interface, connects to SWITCH-A&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: black; font-size: 12pt;"&gt;no nameif&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: black; font-size: 12pt;"&gt;no security-level&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: black; font-size: 12pt;"&gt;no ip address&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: black; font-size: 12pt;"&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: black; font-size: 12pt;"&gt;interface GigabitEthernet1/0&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: black; font-size: 12pt;"&gt;Description Module SSM interface, connects to SWITCH-B&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: black; font-size: 12pt;"&gt;no nameif&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: black; font-size: 12pt;"&gt;no security-level&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: black; font-size: 12pt;"&gt;no ip address&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: black; font-size: 12pt;"&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: black; font-size: 12pt;"&gt;interface Redundant1&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: black; font-size: 12pt;"&gt;member-interface GigabitEthernet0/0&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: black; font-size: 12pt;"&gt;member-interface GigabitEthernet1/0&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: black; font-size: 12pt;"&gt;nameif DMZ&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: black; font-size: 12pt;"&gt;security-level 50&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: black; font-size: 12pt;"&gt;ip address 10.0.0.1 255.255.255.0 standby 10.0.0.254&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt;"&gt;Will the ASA-5520 Firewall allow this setup where I combine two firewall interfaces as a single security zone but then connect each firewall interface to two different switches?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt;"&gt;Am I missing something?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt;"&gt;Thanks for any support!!&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt;"&gt;Frank&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:53:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-zone-across-two-physical-interfaces/m-p/1431311#M746375</guid>
      <dc:creator>fsebera</dc:creator>
      <dc:date>2019-03-11T17:53:57Z</dc:date>
    </item>
    <item>
      <title>Re: Security zone across two physical interfaces</title>
      <link>https://community.cisco.com/t5/network-security/security-zone-across-two-physical-interfaces/m-p/1431312#M746382</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Frank,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both Gig0/0 and Gig0/1 are part of the redundant interface1 &lt;BR /&gt;Only one will be passing traffic, the other will be in standby.&lt;/P&gt;&lt;P&gt;I am not able to test it right now, but I think it should work as long as the 3750 has both g1/0/1 and g1/0/2 on the same VLAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Jun 2010 15:31:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-zone-across-two-physical-interfaces/m-p/1431312#M746382</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-06-02T15:31:30Z</dc:date>
    </item>
    <item>
      <title>Re: Security zone across two physical interfaces</title>
      <link>https://community.cisco.com/t5/network-security/security-zone-across-two-physical-interfaces/m-p/1431313#M746393</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Federico,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ASA-5520 interfaces are G0/0 and G1/0. (Not G0/0 and G0/1)&lt;/P&gt;&lt;P&gt;G0/0 is build into the ASA&lt;/P&gt;&lt;P&gt;G1/0 is on the 4-port module&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Doesyour answer still apply?&lt;/P&gt;&lt;P&gt;Tks&lt;/P&gt;&lt;P&gt;Frank&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Jun 2010 15:36:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-zone-across-two-physical-interfaces/m-p/1431313#M746393</guid>
      <dc:creator>fsebera</dc:creator>
      <dc:date>2010-06-02T15:36:17Z</dc:date>
    </item>
    <item>
      <title>Re: Security zone across two physical interfaces</title>
      <link>https://community.cisco.com/t5/network-security/security-zone-across-two-physical-interfaces/m-p/1431314#M746398</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Frank,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To be honest I don't think it should make any difference that both Gig interfaces on the ASA are on the chassis itself or on the SSM module.&lt;/P&gt;&lt;P&gt;But.... I have not tried it and cannot tell you for sure (i'm just letting you know what I think ;p)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you in a position to test it?&lt;/P&gt;&lt;P&gt;Otherwise I can test it but not at this time &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Jun 2010 15:43:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-zone-across-two-physical-interfaces/m-p/1431314#M746398</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-06-02T15:43:25Z</dc:date>
    </item>
    <item>
      <title>Re: Security zone across two physical interfaces</title>
      <link>https://community.cisco.com/t5/network-security/security-zone-across-two-physical-interfaces/m-p/1431315#M746405</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Federico,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I currently do not have the 4-port module. If the ASA allows the combining of multiple interfaces and then you assign the security zone to the logical interface, it really does not have to forward traffic out both interfaces. Only issue I need to figure out is how to make g0/0 the active and g1/0 the failover.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once fedex drops off my modules, I can test.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again&lt;/P&gt;&lt;P&gt;Frank &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Jun 2010 16:08:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-zone-across-two-physical-interfaces/m-p/1431315#M746405</guid>
      <dc:creator>fsebera</dc:creator>
      <dc:date>2010-06-02T16:08:47Z</dc:date>
    </item>
    <item>
      <title>Re: Security zone across two physical interfaces</title>
      <link>https://community.cisco.com/t5/network-security/security-zone-across-two-physical-interfaces/m-p/1431316#M746417</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes that's correct.&lt;/P&gt;&lt;P&gt;Both interfaces (gig0/0 and gig1/0) will be part of a logical interface.&lt;/P&gt;&lt;P&gt;This redundant logical interface will be the one passing traffic (using the physical gig0/0 as the primary interface and if it fails, using the gig1/0 interface or vice versa).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Jun 2010 18:03:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-zone-across-two-physical-interfaces/m-p/1431316#M746417</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-06-02T18:03:26Z</dc:date>
    </item>
  </channel>
</rss>

