<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VLAN on ASA 5520 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/vlan-on-asa-5520/m-p/1225348#M876331</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I need to do a vpn between two ASA 5520 with the basic IOS, can I do it?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 16 Feb 2009 20:33:26 GMT</pubDate>
    <dc:creator>denaumcisco</dc:creator>
    <dc:date>2009-02-16T20:33:26Z</dc:date>
    <item>
      <title>VLAN on ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/vlan-on-asa-5520/m-p/1225343#M876326</link>
      <description>&lt;P&gt;Good afternoon guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'd like to do a vlan with 2 interfaces and just one IP, can I do it?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 14:51:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-on-asa-5520/m-p/1225343#M876326</guid>
      <dc:creator>denaumcisco</dc:creator>
      <dc:date>2019-03-11T14:51:14Z</dc:date>
    </item>
    <item>
      <title>Re: VLAN on ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/vlan-on-asa-5520/m-p/1225344#M876327</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Denis&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you give a few more details.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use transparent mode where you have 2 vlans with one IP but by the sounds of it this is not what you want. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you asking if the ASA can support IRB (Intergrated Routing/Bridging) where 2 interfaces on your ASA are in the same vlan and share an IP address ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Feb 2009 18:10:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-on-asa-5520/m-p/1225344#M876327</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2009-02-16T18:10:55Z</dc:date>
    </item>
    <item>
      <title>Re: VLAN on ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/vlan-on-asa-5520/m-p/1225345#M876328</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes Jon, something like IRB&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Feb 2009 18:51:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-on-asa-5520/m-p/1225345#M876328</guid>
      <dc:creator>denaumcisco</dc:creator>
      <dc:date>2009-02-16T18:51:24Z</dc:date>
    </item>
    <item>
      <title>Re: VLAN on ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/vlan-on-asa-5520/m-p/1225346#M876329</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Denis&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not aware of the ASA supporting the likes of IRB but then i have never found the need to configure it so i'm not 100% certain on that. I have had a quick look at the configuration docs and couldn't find anything other than transparent mode which is slightly different ie. you bridge together 2 vlans.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunately i don't have access to an ASA to test but i don't think this is supported.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Feb 2009 19:40:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-on-asa-5520/m-p/1225346#M876329</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2009-02-16T19:40:59Z</dc:date>
    </item>
    <item>
      <title>Re: VLAN on ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/vlan-on-asa-5520/m-p/1225347#M876330</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well, I need to link 2 computers into the ASA using necessarily 2 ASA's interfaces.&lt;/P&gt;&lt;P&gt;and I need to put the same IP address on both interfaces, because the computers have the same configuration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anybody?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Feb 2009 19:55:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-on-asa-5520/m-p/1225347#M876330</guid>
      <dc:creator>denaumcisco</dc:creator>
      <dc:date>2009-02-16T19:55:37Z</dc:date>
    </item>
    <item>
      <title>Re: VLAN on ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/vlan-on-asa-5520/m-p/1225348#M876331</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I need to do a vpn between two ASA 5520 with the basic IOS, can I do it?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Feb 2009 20:33:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-on-asa-5520/m-p/1225348#M876331</guid>
      <dc:creator>denaumcisco</dc:creator>
      <dc:date>2009-02-16T20:33:26Z</dc:date>
    </item>
    <item>
      <title>Re: VLAN on ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/vlan-on-asa-5520/m-p/1225349#M876332</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Denis,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In response to your second question: yes, you can configure a basic VPN tunnel between two ASA's. Take a look at the following link for more details and configuration examples:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/ike.html" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/ike.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Feb 2009 03:12:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-on-asa-5520/m-p/1225349#M876332</guid>
      <dc:creator>robertson.michael</dc:creator>
      <dc:date>2009-02-17T03:12:44Z</dc:date>
    </item>
    <item>
      <title>Re: VLAN on ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/vlan-on-asa-5520/m-p/1225350#M876333</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mike,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have a configuration for me to do a vpn between 2 ASA 5520?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried use some commands from the guide that u sent to me , but without sucess&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Feb 2009 23:03:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-on-asa-5520/m-p/1225350#M876333</guid>
      <dc:creator>denaumcisco</dc:creator>
      <dc:date>2009-02-18T23:03:06Z</dc:date>
    </item>
    <item>
      <title>Re: VLAN on ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/vlan-on-asa-5520/m-p/1225351#M876334</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Anybody has a configuration for me to do a vpn between 2 ASA 5520?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried use some commands from the guide isakmp/ipsec , but without sucess&lt;/P&gt;&lt;P&gt;And a solution to a backup route, I found the command "track" on the internet, but didnt work on 5520&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Feb 2009 11:13:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-on-asa-5520/m-p/1225351#M876334</guid>
      <dc:creator>denaumcisco</dc:creator>
      <dc:date>2009-02-19T11:13:58Z</dc:date>
    </item>
    <item>
      <title>Re: VLAN on ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/vlan-on-asa-5520/m-p/1225352#M876335</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is the vpn configuration and the results&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto isakmp policy 10 hash md5&lt;/P&gt;&lt;P&gt;crypto isakmp policy 10 authentication pre-share&lt;/P&gt;&lt;P&gt;crypto isakmp enable outside&lt;/P&gt;&lt;P&gt;crypto map mymap 10 match address 100&lt;/P&gt;&lt;P&gt;access-list 100 permit ip 172.16.3.0 255.255.255.0 172.16.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set myset esp-des esp-hd5-hmac&lt;/P&gt;&lt;P&gt;crypto map mymap 10 set peer 10.22.12.22&lt;/P&gt;&lt;P&gt;crypto map mymap 10 set transform-set myset&lt;/P&gt;&lt;P&gt;crypto map mymap interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rekey SA: 0 (A tunnel will report 1 Active and 1 Rekey SA during rekey)&lt;/P&gt;&lt;P&gt;Total IKE SA: 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1   IKE Peer: 10.12.28.5&lt;/P&gt;&lt;P&gt;    Type    : user            Role    : initiator&lt;/P&gt;&lt;P&gt;    Rekey   : no              State   : MM_WAIT_MSG4&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Feb 2009 11:24:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-on-asa-5520/m-p/1225352#M876335</guid>
      <dc:creator>denaumcisco</dc:creator>
      <dc:date>2009-02-19T11:24:00Z</dc:date>
    </item>
    <item>
      <title>Re: VLAN on ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/vlan-on-asa-5520/m-p/1225353#M876336</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dennis,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you post the configurations on both sides of tunnel? Many of the settings much match. Here is an example that should at least bring the tunnel up:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA1:&lt;/P&gt;&lt;P&gt;crypto isakmp policy 10 hash md5&lt;/P&gt;&lt;P&gt;crypto isakmp policy 10 authentication pre-share &lt;/P&gt;&lt;P&gt;crypto isakmp policy 10 encryption des&lt;/P&gt;&lt;P&gt;crypto isakmp policy 10 group 2&lt;/P&gt;&lt;P&gt;crypto isakmp policy 10 lifetime 86400&lt;/P&gt;&lt;P&gt;crypto isakmp enable outside&lt;/P&gt;&lt;P&gt;crypto map mymap 10 match address 100&lt;/P&gt;&lt;P&gt;access-list 100 permit ip 172.16.3.0 255.255.255.0 172.16.1.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;crypto ipsec transform-set myset esp-des esp-md5-hmac&lt;/P&gt;&lt;P&gt;crypto map mymap 10 set peer 10.22.12.22&lt;/P&gt;&lt;P&gt;crypto map mymap 10 set transform-set myset&lt;/P&gt;&lt;P&gt;crypto map mymap 10 set pfs &lt;/P&gt;&lt;P&gt;crypto map mymap interface outside &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA2:&lt;/P&gt;&lt;P&gt;crypto isakmp policy 10 hash md5&lt;/P&gt;&lt;P&gt;crypto isakmp policy 10 authentication pre-share &lt;/P&gt;&lt;P&gt;crypto isakmp policy 10 encryption des&lt;/P&gt;&lt;P&gt;crypto isakmp policy 10 group 2&lt;/P&gt;&lt;P&gt;crypto isakmp policy 10 lifetime 86400&lt;/P&gt;&lt;P&gt;crypto isakmp enable outside&lt;/P&gt;&lt;P&gt;crypto map mymap 10 match address 100&lt;/P&gt;&lt;P&gt;access-list 100 permit ip 172.16.1.0 255.255.255.0 172.16.3.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;crypto ipsec transform-set myset esp-des esp-md5-hmac&lt;/P&gt;&lt;P&gt;crypto map mymap 10 set peer 10.22.12.21&lt;/P&gt;&lt;P&gt;crypto map mymap 10 set transform-set myset&lt;/P&gt;&lt;P&gt;crypto map mymap 10 set pfs &lt;/P&gt;&lt;P&gt;crypto map mymap interface outside &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As I mentioned, if you are still having trouble, please post your existing configs that exist on each side of the tunnel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Mar 2009 21:53:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-on-asa-5520/m-p/1225353#M876336</guid>
      <dc:creator>robertson.michael</dc:creator>
      <dc:date>2009-03-12T21:53:34Z</dc:date>
    </item>
  </channel>
</rss>

