<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA5510:configure two subnets on one Interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa5510-configure-two-subnets-on-one-interface/m-p/1313199#M858344</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you. The image is 7.08 and the license is very basic. The e0/3 is not licensed.&lt;/P&gt;&lt;P&gt;I have image asa811-smp-k8.bin and asa802-k8.bin come with a CD in the packaged box. Can I just load it and upgrade to the later verison? Does it help?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Encryption hardware device : Cisco ASA-55x0 on-board accelerator (revision 0x0)&lt;/P&gt;&lt;P&gt;                             Boot microcode   : CNlite-MC-Boot-Cisco-1.2&lt;/P&gt;&lt;P&gt;                             SSL/IKE microcode: CNlite-MC-IPSEC-Admin-3.03&lt;/P&gt;&lt;P&gt;                             IPSec microcode  : CNlite-MC-IPSECm-MAIN-2.05&lt;/P&gt;&lt;P&gt; 0: Ext: Ethernet0/0         : address is 0024.97f0.3e68, irq 9&lt;/P&gt;&lt;P&gt; 1: Ext: Ethernet0/1         : address is 0024.97f0.3e69, irq 9&lt;/P&gt;&lt;P&gt; 2: Ext: Ethernet0/2         : address is 0024.97f0.3e6a, irq 9&lt;/P&gt;&lt;P&gt; 3: Ext: Not licensed        : irq 9&lt;/P&gt;&lt;P&gt; 4: Ext: Management0/0       : address is 0024.97f0.3e6c, irq 11&lt;/P&gt;&lt;P&gt; 5: Int: Not used            : irq 11&lt;/P&gt;&lt;P&gt; 6: Int: Not used            : irq 5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Licensed features for this platform:&lt;/P&gt;&lt;P&gt;Maximum Physical Interfaces : 4         &lt;/P&gt;&lt;P&gt;Maximum VLANs               : 10        &lt;/P&gt;&lt;P&gt;Inside Hosts                : Unlimited &lt;/P&gt;&lt;P&gt;Failover                    : Disabled&lt;/P&gt;&lt;P&gt;VPN-DES                     : Enabled   &lt;/P&gt;&lt;P&gt;VPN-3DES-AES                : Enabled   &lt;/P&gt;&lt;P&gt;Security Contexts           : 0         &lt;/P&gt;&lt;P&gt;GTP/GPRS                    : Disabled  &lt;/P&gt;&lt;P&gt;VPN Peers                   : 50        &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 28 Jul 2009 20:28:29 GMT</pubDate>
    <dc:creator>David Lin</dc:creator>
    <dc:date>2009-07-28T20:28:29Z</dc:date>
    <item>
      <title>ASA5510:configure two subnets on one Interface</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-configure-two-subnets-on-one-interface/m-p/1313195#M858340</link>
      <description>&lt;P&gt;I am working on ASA5510 which has 3 ethernet interfaces. I have allocated outside, inside, DMZ for each interface. But I want to configure two subnets on inside interface. &lt;/P&gt;&lt;P&gt;I found there are 4 physical ports in the ethernet interface. The light is on when I pluged a device into the fourth port, but I can't do anything on it. Is it possible to use this port? &lt;/P&gt;&lt;P&gt;If not, can we use management interface as a subnetwork interface? or use subinterface on inside interface?&lt;/P&gt;&lt;P&gt;TIA.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:59:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-configure-two-subnets-on-one-interface/m-p/1313195#M858340</guid>
      <dc:creator>David Lin</dc:creator>
      <dc:date>2019-03-11T15:59:57Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5510:configure two subnets on one Interface</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-configure-two-subnets-on-one-interface/m-p/1313196#M858341</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;David,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have 0,1,2,3  ethernet ports plus manament port interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if  you already allocated 0 as your outside interface and say the inside is  on port 1 you could use dot1q and trunk it to your inside switch,  have the  subinterfaces  in asa inside for your two inside subnets.  The 1 or 0 ports can also operate at gig speed interfaces if your asa has sec plus license, if not sec plus license you can still do dot1q trunking.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gig speed feature&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa72/release/notes/asarn723.html#wp272663" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa72/release/notes/asarn723.html#wp272663&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Subinterfaces&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/intrface.html" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/intrface.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As for the manangement port technically you can use this port as a routed port just like the other ports as long you remove  management only command off that interface, but best is to leave it as management port for management purposes ..  my recommendation is to take advantage of gig speed and use trunking for multiple subnets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jul 2009 17:06:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-configure-two-subnets-on-one-interface/m-p/1313196#M858341</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2009-07-28T17:06:44Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5510:configure two subnets on one Interface</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-configure-two-subnets-on-one-interface/m-p/1313197#M858342</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unfortunately, my ASA5510 has ethernet interface only(it's mistake in the oder). So I have to go for subinterface now.&lt;/P&gt;&lt;P&gt;Just curious, how come the unit has 4 physical ports but the IOS only show 3 interfaces are available(ethernet0/0,0/1,0.2)?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jul 2009 18:50:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-configure-two-subnets-on-one-interface/m-p/1313197#M858342</guid>
      <dc:creator>David Lin</dc:creator>
      <dc:date>2009-07-28T18:50:47Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5510:configure two subnets on one Interface</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-configure-two-subnets-on-one-interface/m-p/1313198#M858343</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi David thanks for rating, most likely  would be the code your asa has.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6120/prod_models_comparison.html" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6120/prod_models_comparison.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Based on ASA comparison and licensing, base license should provide 5 10/100 interfaces which includes the management interface.. so technically you should be able to see all 5 interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the other hand with Sec Plus license shown in red print from above link you will have 2 10/100/1000baseT interfaces and 3 10/100 including management one..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I sort of lean to think it is a code limitation probably under the 7.x code which you probably are running.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jul 2009 20:06:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-configure-two-subnets-on-one-interface/m-p/1313198#M858343</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2009-07-28T20:06:44Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5510:configure two subnets on one Interface</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-configure-two-subnets-on-one-interface/m-p/1313199#M858344</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you. The image is 7.08 and the license is very basic. The e0/3 is not licensed.&lt;/P&gt;&lt;P&gt;I have image asa811-smp-k8.bin and asa802-k8.bin come with a CD in the packaged box. Can I just load it and upgrade to the later verison? Does it help?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Encryption hardware device : Cisco ASA-55x0 on-board accelerator (revision 0x0)&lt;/P&gt;&lt;P&gt;                             Boot microcode   : CNlite-MC-Boot-Cisco-1.2&lt;/P&gt;&lt;P&gt;                             SSL/IKE microcode: CNlite-MC-IPSEC-Admin-3.03&lt;/P&gt;&lt;P&gt;                             IPSec microcode  : CNlite-MC-IPSECm-MAIN-2.05&lt;/P&gt;&lt;P&gt; 0: Ext: Ethernet0/0         : address is 0024.97f0.3e68, irq 9&lt;/P&gt;&lt;P&gt; 1: Ext: Ethernet0/1         : address is 0024.97f0.3e69, irq 9&lt;/P&gt;&lt;P&gt; 2: Ext: Ethernet0/2         : address is 0024.97f0.3e6a, irq 9&lt;/P&gt;&lt;P&gt; 3: Ext: Not licensed        : irq 9&lt;/P&gt;&lt;P&gt; 4: Ext: Management0/0       : address is 0024.97f0.3e6c, irq 11&lt;/P&gt;&lt;P&gt; 5: Int: Not used            : irq 11&lt;/P&gt;&lt;P&gt; 6: Int: Not used            : irq 5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Licensed features for this platform:&lt;/P&gt;&lt;P&gt;Maximum Physical Interfaces : 4         &lt;/P&gt;&lt;P&gt;Maximum VLANs               : 10        &lt;/P&gt;&lt;P&gt;Inside Hosts                : Unlimited &lt;/P&gt;&lt;P&gt;Failover                    : Disabled&lt;/P&gt;&lt;P&gt;VPN-DES                     : Enabled   &lt;/P&gt;&lt;P&gt;VPN-3DES-AES                : Enabled   &lt;/P&gt;&lt;P&gt;Security Contexts           : 0         &lt;/P&gt;&lt;P&gt;GTP/GPRS                    : Disabled  &lt;/P&gt;&lt;P&gt;VPN Peers                   : 50        &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jul 2009 20:28:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-configure-two-subnets-on-one-interface/m-p/1313199#M858344</guid>
      <dc:creator>David Lin</dc:creator>
      <dc:date>2009-07-28T20:28:29Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5510:configure two subnets on one Interface</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-configure-two-subnets-on-one-interface/m-p/1313200#M858345</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you have cco account for software download access load the latest version 8.2(1) [asa821-k8.bin] along with asdm version 6.2 (asdm-621.bin), even though is ED (early deployment) status I have been running it with no issues. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;software download CCO login required&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://tools.cisco.com/support/downloads/go/InterfaceModuleSWT.x?mdfid=279916854&amp;amp;mdfLevel=Model&amp;amp;treeName=Security&amp;amp;modelName=Cisco%20ASA%205510%20Adaptive%20Security%20Appliance&amp;amp;treeMdfId=268438162" target="_blank"&gt;http://tools.cisco.com/support/downloads/go/InterfaceModuleSWT.x?mdfid=279916854&amp;amp;mdfLevel=Model&amp;amp;treeName=Security&amp;amp;modelName=Cisco%20ASA%205510%20Adaptive%20Security%20Appliance&amp;amp;treeMdfId=268438162&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;looked at asa811-smp-k8.bin code,this code is meant to be loaded on ASA5580-20 and ASA5580-40 models only based on software download description notes. You can try 8.0(2) asa802-k8.bin  - this is release notes for 802 for reference &lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa80/release/notes/asarn80.html" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/release/notes/asarn80.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in cd there shoudl be asdm image for 802 version as well, you will need asdm upgrade for 802... but if you have cco access download latest codes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;as usual when upgrading backup current code and asdm immage as well as your config to an tftp server, save the output of "show version" .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;loading the imgage to disk0 should be fairly simple , you can do it through asdm gui or cli which is easier, keep in mind if done through cli  to update boot statement and asdm statements accordingly to reflect new codes.  If you need help let us know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jul 2009 21:33:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-configure-two-subnets-on-one-interface/m-p/1313200#M858345</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2009-07-28T21:33:28Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5510:configure two subnets on one Interface</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-configure-two-subnets-on-one-interface/m-p/1313201#M858346</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;After upgrading the image, I can manage the forth port now!(the license keeps no change, such FO is still disabled)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The another way by using subinterface also works for me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your kind help!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Jul 2009 17:31:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-configure-two-subnets-on-one-interface/m-p/1313201#M858346</guid>
      <dc:creator>David Lin</dc:creator>
      <dc:date>2009-07-29T17:31:23Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5510:configure two subnets on one Interface</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-configure-two-subnets-on-one-interface/m-p/1313202#M858347</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;David, thanks for updating post, glad all working out with new code.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The failover feature is still disabled becuase it is not suported with base license, to use failover down the road when you get another asa5510 will require security plus license on both to use active/standby architecture.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Again thanks for rating .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Jul 2009 22:52:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-configure-two-subnets-on-one-interface/m-p/1313202#M858347</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2009-07-29T22:52:18Z</dc:date>
    </item>
  </channel>
</rss>

