<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sub interface using ASA5510 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/sub-interface-using-asa5510/m-p/1182008#M860487</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On the ASA5510 inside interface, you need to create subinterface (vlans) and name them (nameif) appropriately. You may assign same security-level to all the subinterfaces; if you do, you will need to config the command "same-security-traffic permit inter-interface" in global configuration. I hope this helps&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 26 Apr 2009 06:45:41 GMT</pubDate>
    <dc:creator>gbenga-olubisi</dc:creator>
    <dc:date>2009-04-26T06:45:41Z</dc:date>
    <item>
      <title>Sub interface using ASA5510</title>
      <link>https://community.cisco.com/t5/network-security/sub-interface-using-asa5510/m-p/1182006#M860485</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have ASA5510 whose INSIDE interface is connected to a Cisco Cat 2960G switch (L2),Now I have 3 VLAN configured in the Cisco2960G,and a TRUNK port is connected to a ASA5510 Inside interface,that inside interface is configured as a TRUNK,which is automatic (802.1q enabled),in this case Is it possible to have the Inter VLAN communication between these 3 VLANs.If so,how to do it,or is there any requirement of L3 switch or router to have this interVLAN communication?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please clarify my doubts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Newzion123.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:23:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sub-interface-using-asa5510/m-p/1182006#M860485</guid>
      <dc:creator>newzion123</dc:creator>
      <dc:date>2019-03-11T15:23:33Z</dc:date>
    </item>
    <item>
      <title>Re: Sub interface using ASA5510</title>
      <link>https://community.cisco.com/t5/network-security/sub-interface-using-asa5510/m-p/1182007#M860486</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Newzion123&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes the ASA will allow the inter-vlan communication so you don't need an additional L3 switch/router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First for configuring subinterfaces - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/intrface.html#wp1044006" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/intrface.html#wp1044006&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;then you can either &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) give each subinterface a different security level and setup NAT and access-lists as you would with normal physical interfaces &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) give the subinterfaces the same security level and then add this to your config - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA(config)# same-security-traffic permit inter-interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/intparam.html#wp1039276" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/intparam.html#wp1039276&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 25 Apr 2009 13:57:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sub-interface-using-asa5510/m-p/1182007#M860486</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2009-04-25T13:57:11Z</dc:date>
    </item>
    <item>
      <title>Re: Sub interface using ASA5510</title>
      <link>https://community.cisco.com/t5/network-security/sub-interface-using-asa5510/m-p/1182008#M860487</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On the ASA5510 inside interface, you need to create subinterface (vlans) and name them (nameif) appropriately. You may assign same security-level to all the subinterfaces; if you do, you will need to config the command "same-security-traffic permit inter-interface" in global configuration. I hope this helps&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 26 Apr 2009 06:45:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sub-interface-using-asa5510/m-p/1182008#M860487</guid>
      <dc:creator>gbenga-olubisi</dc:creator>
      <dc:date>2009-04-26T06:45:41Z</dc:date>
    </item>
    <item>
      <title>Re: Sub interface using ASA5510</title>
      <link>https://community.cisco.com/t5/network-security/sub-interface-using-asa5510/m-p/1182009#M860488</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ji Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks a lot for extending your support,i will try doing the same and let me inform you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;newzion.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 26 Apr 2009 11:44:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sub-interface-using-asa5510/m-p/1182009#M860488</guid>
      <dc:creator>newzion123</dc:creator>
      <dc:date>2009-04-26T11:44:03Z</dc:date>
    </item>
    <item>
      <title>Re: Sub interface using ASA5510</title>
      <link>https://community.cisco.com/t5/network-security/sub-interface-using-asa5510/m-p/1182010#M860489</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks ,I will try this....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Newzion123&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 26 Apr 2009 11:48:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sub-interface-using-asa5510/m-p/1182010#M860489</guid>
      <dc:creator>newzion123</dc:creator>
      <dc:date>2009-04-26T11:48:39Z</dc:date>
    </item>
    <item>
      <title>Re: Sub interface using ASA5510</title>
      <link>https://community.cisco.com/t5/network-security/sub-interface-using-asa5510/m-p/1182011#M860490</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;inter-vlan routing in PIX/ASA is not working as it is intended to...i believe PIX/ASA have an L3 engine which takes care of this routing stuff (as otherwise, it would not have support for RIP and OSPF in v7.2)...but for some reasons, i am not able to get the box do it...any help from the experts would be greatly appreciated...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have the following topology&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FW1(PIX)---FW2(PIX) &lt;/P&gt;&lt;P&gt;  |          |&lt;/P&gt;&lt;P&gt;  |          |&lt;/P&gt;&lt;P&gt;CoreSw1---CoreSw2&lt;/P&gt;&lt;P&gt;  |          |&lt;/P&gt;&lt;P&gt;   \        /&lt;/P&gt;&lt;P&gt;    \      /&lt;/P&gt;&lt;P&gt;   AccessSwitch&lt;/P&gt;&lt;P&gt;       / \&lt;/P&gt;&lt;P&gt;      /   \&lt;/P&gt;&lt;P&gt;    PC1   PC2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the relevant configurations from my PIX is below...PIX1 and PIX2 are in Failover Cluster Mode...no question of NAT as i have disabled it using the Global configuration command "no nat-control"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface e1&lt;/P&gt;&lt;P&gt;nameif TRUNK&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;no ip address&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface e1.10&lt;/P&gt;&lt;P&gt;vlan 10&lt;/P&gt;&lt;P&gt;nameif RMS-SD&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;ip address 10.116.205.130 255.255.255.128&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface e1.80&lt;/P&gt;&lt;P&gt;vlan 80&lt;/P&gt;&lt;P&gt;nameif RMS-DS&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;ip address 10.116.217.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inbound_in extended permit ip any any&lt;/P&gt;&lt;P&gt;access-list outbound_out extended permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group inbound_in in RMS-SD&lt;/P&gt;&lt;P&gt;access-group inbound_in in RMS-DS&lt;/P&gt;&lt;P&gt;access-group outbound_out out RMS-SD&lt;/P&gt;&lt;P&gt;access-group outbound_out out RMS-DS&lt;/P&gt;&lt;P&gt;access-group inbound_in in TRUNK&lt;/P&gt;&lt;P&gt;access-group outbound_out out TRUNK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;same-security-level permit inter-interface-traffic&lt;/P&gt;&lt;P&gt;same-security-level permit intra-interface-traffic&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PC1 Gateway (PIX) : 10.116.205.130&lt;/P&gt;&lt;P&gt;PC1 interface IP : 10.116.205.132&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PC2 Gateway (PIX) : 10.116.217.1&lt;/P&gt;&lt;P&gt;PC2 interface IP : 10.116.217.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am able to PING the Gateway(PIX) of PC1 from PC1 and the Gateway(PIX) of PC2 from PC2. But I am not able to reach/ping PC2 from PC1 and vice-versa.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Apr 2009 06:13:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sub-interface-using-asa5510/m-p/1182011#M860490</guid>
      <dc:creator>cannan.ilangovan</dc:creator>
      <dc:date>2009-04-27T06:13:43Z</dc:date>
    </item>
    <item>
      <title>Re: Sub interface using ASA5510</title>
      <link>https://community.cisco.com/t5/network-security/sub-interface-using-asa5510/m-p/1182012#M860491</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i was wrong...it indeed was working...i was attempting to ping the gateway IP of PC1 from PC2 and vice-versa which is NOT working though..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but my attempt to ping PC1 from PC2 and vice-vera was successful...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks to all experts for their suggestions!!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Apr 2009 07:48:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sub-interface-using-asa5510/m-p/1182012#M860491</guid>
      <dc:creator>cannan.ilangovan</dc:creator>
      <dc:date>2009-04-27T07:48:27Z</dc:date>
    </item>
  </channel>
</rss>

