<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Connecting ASA 5505 to Layer 2 Switch on VLan in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/connecting-asa-5505-to-layer-2-switch-on-vlan/m-p/1353683#M748368</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can certainly understand the confusion when it comes to ASA5505 and vlans.&amp;nbsp; Once you do it once, you will realize how easy it is.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Here is a link with a sample config: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://ezinearticles.com/?Basic-Configuration-Tutorial-For-the-Cisco-ASA-5505-Firewall&amp;amp;id=1681858"&gt;http://ezinearticles.com/?Basic-Configuration-Tutorial-For-the-Cisco-ASA-5505-Firewall&amp;amp;id=1681858&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You create a layer 3 interface for outside vlan&lt;/P&gt;&lt;P&gt;you create a layer 3 interface for inside vlan&lt;/P&gt;&lt;P&gt;configure one port on outside vlan&lt;/P&gt;&lt;P&gt;configure other ports on inside vlan (by default it will be in vlan1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;now, it is just like a asa5510. The nameif and security lines go under the "int vlan&lt;BLAH&gt;" section.&lt;/BLAH&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 05 Mar 2010 17:03:47 GMT</pubDate>
    <dc:creator>Kureli Sankar</dc:creator>
    <dc:date>2010-03-05T17:03:47Z</dc:date>
    <item>
      <title>Connecting ASA 5505 to Layer 2 Switch on VLan</title>
      <link>https://community.cisco.com/t5/network-security/connecting-asa-5505-to-layer-2-switch-on-vlan/m-p/1353682#M748356</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I really need someones help with this I am a bit stumped.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We recently purchased a new internet link. The ISP has provided their own equipment which we dont have access to.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On this equipment they have created two Vlans. One for internet traffic and one for an extended WAN to another location.&amp;nbsp; The internet link is on VLan 183 on their equipment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The advised me to connected a Layer 2 Switch directly to the port they had configured VLan 183 on. On the switch I created my own VLan also called 183, trunked it and added a few local switch ports to this Vlan. If I connect my laptop into one of the ports assigned to my Vlan and set my laptops IP to the static information provided by the ISP I can surf the net.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I now need to hook my ASA up to this switch. I need my outside interface to point to the following&lt;/P&gt;&lt;P&gt;ip - 77.75.100.194&lt;/P&gt;&lt;P&gt;mask 255.255.255.252&lt;/P&gt;&lt;P&gt;gateway 77.75.100.193&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My inside interface to&lt;/P&gt;&lt;P&gt;10.255.251.211&lt;/P&gt;&lt;P&gt;255.255.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need all traffic on the 10.255.0.0 network to be able to use this new internet link&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I suppose Im just really confused about how I link the ASA up with the Vlan'd switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the past I have always hooked the ASA up direct to whatever router was provided but the VLAN in the middle is confusing me. Also I have only ever used 5510's and the 5505 seems slightly different.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If someone could point me in the right direction I would really appreciate it!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you!!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:18:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connecting-asa-5505-to-layer-2-switch-on-vlan/m-p/1353682#M748356</guid>
      <dc:creator>drikilbride</dc:creator>
      <dc:date>2019-03-11T17:18:07Z</dc:date>
    </item>
    <item>
      <title>Re: Connecting ASA 5505 to Layer 2 Switch on VLan</title>
      <link>https://community.cisco.com/t5/network-security/connecting-asa-5505-to-layer-2-switch-on-vlan/m-p/1353683#M748368</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can certainly understand the confusion when it comes to ASA5505 and vlans.&amp;nbsp; Once you do it once, you will realize how easy it is.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Here is a link with a sample config: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://ezinearticles.com/?Basic-Configuration-Tutorial-For-the-Cisco-ASA-5505-Firewall&amp;amp;id=1681858"&gt;http://ezinearticles.com/?Basic-Configuration-Tutorial-For-the-Cisco-ASA-5505-Firewall&amp;amp;id=1681858&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You create a layer 3 interface for outside vlan&lt;/P&gt;&lt;P&gt;you create a layer 3 interface for inside vlan&lt;/P&gt;&lt;P&gt;configure one port on outside vlan&lt;/P&gt;&lt;P&gt;configure other ports on inside vlan (by default it will be in vlan1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;now, it is just like a asa5510. The nameif and security lines go under the "int vlan&lt;BLAH&gt;" section.&lt;/BLAH&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Mar 2010 17:03:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connecting-asa-5505-to-layer-2-switch-on-vlan/m-p/1353683#M748368</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-03-05T17:03:47Z</dc:date>
    </item>
    <item>
      <title>Re: Connecting ASA 5505 to Layer 2 Switch on VLan</title>
      <link>https://community.cisco.com/t5/network-security/connecting-asa-5505-to-layer-2-switch-on-vlan/m-p/1353684#M748374</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are a life saver! I'll give that a try Monday when I'm back in the office!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again for your help!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Mar 2010 17:07:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connecting-asa-5505-to-layer-2-switch-on-vlan/m-p/1353684#M748374</guid>
      <dc:creator>drikilbride</dc:creator>
      <dc:date>2010-03-05T17:07:55Z</dc:date>
    </item>
    <item>
      <title>Re: Connecting ASA 5505 to Layer 2 Switch on VLan</title>
      <link>https://community.cisco.com/t5/network-security/connecting-asa-5505-to-layer-2-switch-on-vlan/m-p/1353685#M748380</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried that but am still not able to get out onto the internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am going to post my configs for both the ASA 5505 and my Cisco 2950 Switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe someone could spot what I have missed?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance!!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Mar 2010 12:23:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connecting-asa-5505-to-layer-2-switch-on-vlan/m-p/1353685#M748380</guid>
      <dc:creator>drikilbride</dc:creator>
      <dc:date>2010-03-08T12:23:55Z</dc:date>
    </item>
    <item>
      <title>Re: Connecting ASA 5505 to Layer 2 Switch on VLan</title>
      <link>https://community.cisco.com/t5/network-security/connecting-asa-5505-to-layer-2-switch-on-vlan/m-p/1353686#M748385</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The config looks correct.&lt;/P&gt;&lt;P&gt;Are you able to ping xx.xx.xx.xx ?&lt;/P&gt;&lt;P&gt;interface Vlan2&lt;BR /&gt; nameif outside&lt;BR /&gt; security-level 0&lt;BR /&gt; ip address xx.xx.xx.xx 255.255.255.252&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 xx.xx.xx.xx 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you able to ping xx.xx.xx.xx??&lt;/P&gt;&lt;P&gt;I hope ip address in vlan2 and the default route are not the same IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ping the outside default gw from the firewall and collect captures and see what they say.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cap capout int outside match icmp any any&lt;/P&gt;&lt;P&gt;sh cap capout&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;check the logs as well&lt;/P&gt;&lt;P&gt;conf t&lt;/P&gt;&lt;P&gt;logging on&lt;/P&gt;&lt;P&gt;logging buffered 7&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh logg | i x.x.x.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;where x.x.x.x is the host that is try to go to the internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Mar 2010 14:43:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connecting-asa-5505-to-layer-2-switch-on-vlan/m-p/1353686#M748385</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-03-08T14:43:51Z</dc:date>
    </item>
    <item>
      <title>Re: Connecting ASA 5505 to Layer 2 Switch on VLan</title>
      <link>https://community.cisco.com/t5/network-security/connecting-asa-5505-to-layer-2-switch-on-vlan/m-p/1353687#M748388</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can ping the following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VLAN2&lt;/P&gt;&lt;P&gt;IP Address xx.xx.xx.xx 255.255.255.252&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't ping the default gateway route outside 0.0.0.0 0.0.0.0 x.x.x.x 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The IP Address used in VLAN2 and the default gateway are different, both provided by the ISP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The thing is, if I hook my laptop up direct to the Switch and statically assign it the IP, Gateway and DNS from ISP I have full internet access. There just seems to be an issue with the ASA and the trunked 802.1q switch port. (which works fine with the laptop)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have attached the log from when I pinged the VLAN2 address from the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Mar 2010 16:45:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connecting-asa-5505-to-layer-2-switch-on-vlan/m-p/1353687#M748388</guid>
      <dc:creator>drikilbride</dc:creator>
      <dc:date>2010-03-08T16:45:23Z</dc:date>
    </item>
    <item>
      <title>Re: Connecting ASA 5505 to Layer 2 Switch on VLan</title>
      <link>https://community.cisco.com/t5/network-security/connecting-asa-5505-to-layer-2-switch-on-vlan/m-p/1353688#M748392</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Seems like you need to configured vlan 183 and move the config from vlan2 to vlan183.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan183&lt;BR /&gt; nameif outside&lt;BR /&gt; security-level 0&lt;BR /&gt; ip address xx.xx.xx.xx 255.255.255.252&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/0&lt;BR /&gt; switchport access vlan 183&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pls. double check the trunk config and the vlan and see which one it is supposed to be.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Mar 2010 18:27:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connecting-asa-5505-to-layer-2-switch-on-vlan/m-p/1353688#M748392</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-03-08T18:27:29Z</dc:date>
    </item>
    <item>
      <title>Re: Connecting ASA 5505 to Layer 2 Switch on VLan</title>
      <link>https://community.cisco.com/t5/network-security/connecting-asa-5505-to-layer-2-switch-on-vlan/m-p/1353689#M748395</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Its working!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a mil for all your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Changing the VLAN to VLAN 183 did the trick!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Mar 2010 11:23:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connecting-asa-5505-to-layer-2-switch-on-vlan/m-p/1353689#M748395</guid>
      <dc:creator>drikilbride</dc:creator>
      <dc:date>2010-03-09T11:23:41Z</dc:date>
    </item>
  </channel>
</rss>

