<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: V-Lans in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/v-lans/m-p/1164062#M877253</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Vinay,&lt;/P&gt;&lt;P&gt;Assuming you have this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fw: &lt;/P&gt;&lt;P&gt;vlan100&lt;/P&gt;&lt;P&gt;Int vl 100&lt;/P&gt;&lt;P&gt;Ip address  192.168.12.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Int eth 0/1&lt;/P&gt;&lt;P&gt;nameif Inside&lt;/P&gt;&lt;P&gt;switchport access vl100&lt;/P&gt;&lt;P&gt;no shut&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Switchport connected to fw's inside:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Switchport access vl100&lt;/P&gt;&lt;P&gt;switchport mode access&lt;/P&gt;&lt;P&gt;no shut&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This should work , assuming there is no ACL which denies the traffic/icmp packets.&lt;/P&gt;&lt;P&gt;Vlad&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vinay ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A small corection, sorry!&lt;/P&gt;&lt;P&gt;The fw should be like this not what I previously posted:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vlan100&lt;/P&gt;&lt;P&gt;Int vl 100&lt;/P&gt;&lt;P&gt;Nameif Inside&lt;/P&gt;&lt;P&gt;Ip address  192.168.12.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Int eth 0/1&lt;/P&gt;&lt;P&gt;switchport access vl100&lt;/P&gt;&lt;P&gt;no shut&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 25 Jan 2009 10:24:24 GMT</pubDate>
    <dc:creator>hunnetvl01</dc:creator>
    <dc:date>2009-01-25T10:24:24Z</dc:date>
    <item>
      <title>V-Lans</title>
      <link>https://community.cisco.com/t5/network-security/v-lans/m-p/1164059#M877248</link>
      <description>&lt;P&gt;Hi, I have to setup new V-lans department wise in our office. In current scenario, we have unmanaged switch which is connected with ASA 5505 FW where V-LAN 100 (NOC) is created and IP address of Inside Interface NOC V-lan is 192.168.12.1 which is a gateway set on client machines and Servers. This Network is connected with Remote sites via STS Tunnel. Now we want to make a new V-lans on new L2 switch and put the access list according to rights of users. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here, I am bit confused about understanding new V-Lans structure. I want that the IT department and the Servers are remained in the NOC V-lan but would like to make seperate V-Lans for DEV and QA Team. I have created three following V-lans on L2 switch:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Vlan 100 NOC Port assigned eth 1-4&lt;/P&gt;&lt;P&gt;2) Vlan 200 DEV Port assigned eth 5-8&lt;/P&gt;&lt;P&gt;3) Vlan 300 QA  Port assigned eth 9-12&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I want to connect ASA Inside NOC Vlan 100 with the port 1 L2 switch where already same V-lan created but when I connect switch and FW and connect my laptop on port 2 of L2 switch then I am not able to ping the Inside Interface IP 192.168.12.1. Not able to underst&lt;/P&gt;&lt;P&gt;and where I am wrong. Second, I want to make a Trunk port on L2 switch on port 14 and connect with FW port 8 which is not a member of V-lan and want to do all settings on FW Trunk port like nattig, access list or etc. Please advice your suggestions in this regard. Can you please recommend how many network design I can use, Pl suggest as well if possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Vinay Gupta&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 14:41:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/v-lans/m-p/1164059#M877248</guid>
      <dc:creator>nikuhappy2010</dc:creator>
      <dc:date>2019-03-11T14:41:43Z</dc:date>
    </item>
    <item>
      <title>Re: V-Lans</title>
      <link>https://community.cisco.com/t5/network-security/v-lans/m-p/1164060#M877250</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Vinay,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Paste the ASA and switch config.&lt;/P&gt;&lt;P&gt;I suppose the Vlans on teh fw are named the same as the vlan on the switch and u connect vlan 100 on switch with an interface assigned Vlan 100 on the fw.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vlad&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 24 Jan 2009 18:58:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/v-lans/m-p/1164060#M877250</guid>
      <dc:creator>hunnetvl01</dc:creator>
      <dc:date>2009-01-24T18:58:12Z</dc:date>
    </item>
    <item>
      <title>Re: V-Lans</title>
      <link>https://community.cisco.com/t5/network-security/v-lans/m-p/1164061#M877252</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes, you are right....then should it not be start the communication between switch and FW by creating same VLan name and ID. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 25 Jan 2009 02:43:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/v-lans/m-p/1164061#M877252</guid>
      <dc:creator>nikuhappy2010</dc:creator>
      <dc:date>2009-01-25T02:43:10Z</dc:date>
    </item>
    <item>
      <title>Re: V-Lans</title>
      <link>https://community.cisco.com/t5/network-security/v-lans/m-p/1164062#M877253</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Vinay,&lt;/P&gt;&lt;P&gt;Assuming you have this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fw: &lt;/P&gt;&lt;P&gt;vlan100&lt;/P&gt;&lt;P&gt;Int vl 100&lt;/P&gt;&lt;P&gt;Ip address  192.168.12.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Int eth 0/1&lt;/P&gt;&lt;P&gt;nameif Inside&lt;/P&gt;&lt;P&gt;switchport access vl100&lt;/P&gt;&lt;P&gt;no shut&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Switchport connected to fw's inside:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Switchport access vl100&lt;/P&gt;&lt;P&gt;switchport mode access&lt;/P&gt;&lt;P&gt;no shut&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This should work , assuming there is no ACL which denies the traffic/icmp packets.&lt;/P&gt;&lt;P&gt;Vlad&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vinay ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A small corection, sorry!&lt;/P&gt;&lt;P&gt;The fw should be like this not what I previously posted:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vlan100&lt;/P&gt;&lt;P&gt;Int vl 100&lt;/P&gt;&lt;P&gt;Nameif Inside&lt;/P&gt;&lt;P&gt;Ip address  192.168.12.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Int eth 0/1&lt;/P&gt;&lt;P&gt;switchport access vl100&lt;/P&gt;&lt;P&gt;no shut&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 25 Jan 2009 10:24:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/v-lans/m-p/1164062#M877253</guid>
      <dc:creator>hunnetvl01</dc:creator>
      <dc:date>2009-01-25T10:24:24Z</dc:date>
    </item>
  </channel>
</rss>

