<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA VLAN 1 connection to different VLAN in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-vlan-1-connection-to-different-vlan/m-p/1315284#M807104</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks to all for your assistance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 03 Dec 2009 23:43:58 GMT</pubDate>
    <dc:creator>sadik.bash</dc:creator>
    <dc:date>2009-12-03T23:43:58Z</dc:date>
    <item>
      <title>ASA VLAN 1 connection to different VLAN</title>
      <link>https://community.cisco.com/t5/network-security/asa-vlan-1-connection-to-different-vlan/m-p/1315278#M807078</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will be setting up a LAN(PCs and Laptops) at a customter's site. The customer offered to provide me with connections on their core switch on a separate VLAN. I will setup an Cisco ASA5505 on the edge connected to router. So, here is the toplogy:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; PC to Customer's Core Switch (VLAN125)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ASA int E0/1 VLAN1 to Customer's Core Switch (VLAN125)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to know if this configuration would work. Also, can I ping from the PC to the global int (E0/0 VLAN2) and LAN int of the router which has a public IP address?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;sK&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:45:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vlan-1-connection-to-different-vlan/m-p/1315278#M807078</guid>
      <dc:creator>sadik.bash</dc:creator>
      <dc:date>2019-03-11T16:45:29Z</dc:date>
    </item>
    <item>
      <title>Re: ASA VLAN 1 connection to different VLAN</title>
      <link>https://community.cisco.com/t5/network-security/asa-vlan-1-connection-to-different-vlan/m-p/1315279#M807080</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sadik,&lt;/P&gt;&lt;P&gt;The topology isnt' clear. Pls. clarify.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which is E0/0 vlan2?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PC--vlan125--swtich---vlan1--ASA-vlan2--Router--internet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are asking if you can ping from the PC to the ASA's vlan2 interface? If so the answer is NO.&lt;/P&gt;&lt;P&gt;But you can ping from the PC to the Router's vlan2 interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The reason is you can only ping the closest interface to your client. You canno ping the far side interface of the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Dec 2009 21:03:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vlan-1-connection-to-different-vlan/m-p/1315279#M807080</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2009-12-03T21:03:47Z</dc:date>
    </item>
    <item>
      <title>Re: ASA VLAN 1 connection to different VLAN</title>
      <link>https://community.cisco.com/t5/network-security/asa-vlan-1-connection-to-different-vlan/m-p/1315280#M807087</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry if I wasn't clear.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the clarificaiton:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PC plugged into VLAN125 of customer's Switch&lt;/P&gt;&lt;P&gt;Inside Interface E0/1 (VLAN1) on the ASA plugged into the VLAN125 of customer's switch&lt;/P&gt;&lt;P&gt;Global Interface E0/0(VLAN2) on the ASA plugged into the router (FA0/0)&lt;/P&gt;&lt;P&gt;Router S0/0 connects to Internet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, the question is if I ping the ASA Inside interface from the PC, would this work? And also, let's say PC IP is 172.16.2.100 and Inside ASA int E0/1 VLAN1 IP is 172.16.2.1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;sK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Dec 2009 21:45:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vlan-1-connection-to-different-vlan/m-p/1315280#M807087</guid>
      <dc:creator>sadik.bash</dc:creator>
      <dc:date>2009-12-03T21:45:26Z</dc:date>
    </item>
    <item>
      <title>Re: ASA VLAN 1 connection to different VLAN</title>
      <link>https://community.cisco.com/t5/network-security/asa-vlan-1-connection-to-different-vlan/m-p/1315281#M807089</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As long as the switch can route between blan125 and vlan1 you should be able to ping from the pc to vlan 1(inside).&lt;/P&gt;&lt;P&gt;The ASA will not let you ping vlan2 though from the pc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Dec 2009 22:39:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vlan-1-connection-to-different-vlan/m-p/1315281#M807089</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2009-12-03T22:39:44Z</dc:date>
    </item>
    <item>
      <title>Re: ASA VLAN 1 connection to different VLAN</title>
      <link>https://community.cisco.com/t5/network-security/asa-vlan-1-connection-to-different-vlan/m-p/1315282#M807097</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the repoly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure if the customer would enable that; however, as a solution, should I create a matching VLAN, VLAN125, on the inside ASA interface so routing wouldn't required?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in adavance,&lt;/P&gt;&lt;P&gt;sK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Dec 2009 23:15:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vlan-1-connection-to-different-vlan/m-p/1315282#M807097</guid>
      <dc:creator>sadik.bash</dc:creator>
      <dc:date>2009-12-03T23:15:11Z</dc:date>
    </item>
    <item>
      <title>Re: ASA VLAN 1 connection to different VLAN</title>
      <link>https://community.cisco.com/t5/network-security/asa-vlan-1-connection-to-different-vlan/m-p/1315283#M807101</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;sadik.bash wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry if I wasn't clear.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the clarificaiton:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PC plugged into VLAN125 of customer's Switch&lt;/P&gt;&lt;P&gt;Inside Interface E0/1 (VLAN1) on the ASA plugged into the VLAN125 of customer's switch&lt;/P&gt;&lt;P&gt;Global Interface E0/0(VLAN2) on the ASA plugged into the router (FA0/0)&lt;/P&gt;&lt;P&gt;Router S0/0 connects to Internet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, the question is if I ping the ASA Inside interface from the PC, would this work? And also, let's say PC IP is 172.16.2.100 and Inside ASA int E0/1 VLAN1 IP is 172.16.2.1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;sK&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;sK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's not clear what you mean when you say "Inside interface E0/1 (VLAN1) on ASA plugged into vlan 125 of customer switch"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the interface is connected to a port on the switch that is configured to be in vlan 125 then the ASA interface is not in vlan 1 at all but vlan 125.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So as long as the PC and the ASA connect to ports configured as vlan 125 and the PC and ASA have an IP address from the same subnet then you will not need routing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Dec 2009 23:24:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vlan-1-connection-to-different-vlan/m-p/1315283#M807101</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2009-12-03T23:24:28Z</dc:date>
    </item>
    <item>
      <title>Re: ASA VLAN 1 connection to different VLAN</title>
      <link>https://community.cisco.com/t5/network-security/asa-vlan-1-connection-to-different-vlan/m-p/1315284#M807104</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks to all for your assistance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Dec 2009 23:43:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vlan-1-connection-to-different-vlan/m-p/1315284#M807104</guid>
      <dc:creator>sadik.bash</dc:creator>
      <dc:date>2009-12-03T23:43:58Z</dc:date>
    </item>
  </channel>
</rss>

