<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Asa 8.x using Trunking and Vlans to get more ports in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-8-x-using-trunking-and-vlans-to-get-more-ports/m-p/982854#M919002</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Doug, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for number 1) and 2)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For above requirements do each requires to have its own physical interface? if so then you are leting pass trunking feature asa 7.x and above provides you could accomplish inside/outside/dmz1  off one interface with trunking. Use the management interface if you get security plus license  and make it a routed port and do your failover using that physical interface. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in above scenarion you will have used two physical ports and still have three physical ports left.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;now if you need physical interfaces you could do one interface for inside one for outside&lt;/P&gt;&lt;P&gt;use mgt interface for failover,you still have two physical interfaces left,use one of these two for DMZ1/DMZ2 and/or any extranet interfaces needed using 802.1q.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;I&gt;Is this some hidden feature that Cisco doesn't want users to know about so they will purchase the 4port GigE card for the ASA that costs more than the 5510 itself? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/I&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no hidden features Im aware of, simply it comes down to using 802.1q trunking and subinterfaces, remember with sec plus you have up to 100 Virtual interfaces for the entire asa5510 unit and all be able to use &lt;B&gt;nameif&lt;/B&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;-Jorge &lt;/P&gt;&lt;P&gt;&lt;I&gt;PLS rate any helpful post if it helped&lt;/I&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 03 Jun 2008 23:42:07 GMT</pubDate>
    <dc:creator>JORGE RODRIGUEZ</dc:creator>
    <dc:date>2008-06-03T23:42:07Z</dc:date>
    <item>
      <title>Asa 8.x using Trunking and Vlans to get more ports</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-x-using-trunking-and-vlans-to-get-more-ports/m-p/982850#M918991</link>
      <description>&lt;P&gt;I have been searching CCO to find a config guide that shows how to setup an ASA running 7.2 or 8.x trunking to a L3 switch. Getting an 5510 and I need 7 interfaces, so I am two short. I will be getting the Security Plus so I can do failover. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where is this config guide, does it exist?  I see one for the 5505, but that isn't the 5510. thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:54:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-x-using-trunking-and-vlans-to-get-more-ports/m-p/982850#M918991</guid>
      <dc:creator>dmooreami</dc:creator>
      <dc:date>2019-03-11T12:54:45Z</dc:date>
    </item>
    <item>
      <title>Re: Asa 8.x using Trunking and Vlans to get more ports</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-x-using-trunking-and-vlans-to-get-more-ports/m-p/982851#M918994</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here you go, basic reference 802.1q and subinterfaces&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/intrface.html" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/intrface.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you need fruther assistance let me know to help you with a basic script but it is very stright forward, creating your subinterfaces with appropriate sec levels if they are DMZs , there is not trunking specific command in ASA, once you create subinterfaces and physically connect the ASA interface to your switch trunk thats prety much it, create your trunk on the switch and allow the vlans you want. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may use this thread as reference.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;CommCmd=MB%3Fcmd%3Dpass_through%26location%3Doutline%40%5E1%40.2cbf5ff2/0#selected_message" target="_blank"&gt;http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;CommCmd=MB%3Fcmd%3Dpass_through%26location%3Doutline%40%5E1%40.2cbf5ff2/0#selected_message&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bst Rgds&lt;/P&gt;&lt;P&gt;-Jorge&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jun 2008 19:25:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-x-using-trunking-and-vlans-to-get-more-ports/m-p/982851#M918994</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-06-03T19:25:56Z</dc:date>
    </item>
    <item>
      <title>Re: Asa 8.x using Trunking and Vlans to get more ports</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-x-using-trunking-and-vlans-to-get-more-ports/m-p/982852#M918996</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Version 7.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/intrface.html#wp1044006" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/intrface.html#wp1044006&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Version 8.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/intrface.html#wp1044006" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/intrface.html#wp1044006&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jun 2008 19:30:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-x-using-trunking-and-vlans-to-get-more-ports/m-p/982852#M918996</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2008-06-03T19:30:03Z</dc:date>
    </item>
    <item>
      <title>Re: Asa 8.x using Trunking and Vlans to get more ports</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-x-using-trunking-and-vlans-to-get-more-ports/m-p/982853#M919000</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, I have read that before. It looks like to me I can use both the physical ports as before and Trunking/VLAN features.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I need is this.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1)Use the physical NameIf itnerfaces on ASA for inside/outside/dmz1/failover. I realize that that will require setting up the Mgt interface as a "real interface" and not mgt interface. There is a tech note on doing that&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2)Use the 5th port on the ASA  with VLAN/Trunking to support Dmz2/Extranet  interfaces via the 6500 switch. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is still no example as to what the finished ASA config looks like here on the cisco site.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Typically cisco will have a config guide with diagrams, device configs and traffic flows. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this some hidden feature that Cisco doesn't want users to know about so they will purchase the 4port GigE card for the ASA that costs more than the 5510 itself?  &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jun 2008 19:51:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-x-using-trunking-and-vlans-to-get-more-ports/m-p/982853#M919000</guid>
      <dc:creator>dmooreami</dc:creator>
      <dc:date>2008-06-03T19:51:52Z</dc:date>
    </item>
    <item>
      <title>Re: Asa 8.x using Trunking and Vlans to get more ports</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-x-using-trunking-and-vlans-to-get-more-ports/m-p/982854#M919002</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Doug, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for number 1) and 2)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For above requirements do each requires to have its own physical interface? if so then you are leting pass trunking feature asa 7.x and above provides you could accomplish inside/outside/dmz1  off one interface with trunking. Use the management interface if you get security plus license  and make it a routed port and do your failover using that physical interface. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in above scenarion you will have used two physical ports and still have three physical ports left.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;now if you need physical interfaces you could do one interface for inside one for outside&lt;/P&gt;&lt;P&gt;use mgt interface for failover,you still have two physical interfaces left,use one of these two for DMZ1/DMZ2 and/or any extranet interfaces needed using 802.1q.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;I&gt;Is this some hidden feature that Cisco doesn't want users to know about so they will purchase the 4port GigE card for the ASA that costs more than the 5510 itself? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/I&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no hidden features Im aware of, simply it comes down to using 802.1q trunking and subinterfaces, remember with sec plus you have up to 100 Virtual interfaces for the entire asa5510 unit and all be able to use &lt;B&gt;nameif&lt;/B&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;-Jorge &lt;/P&gt;&lt;P&gt;&lt;I&gt;PLS rate any helpful post if it helped&lt;/I&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jun 2008 23:42:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-x-using-trunking-and-vlans-to-get-more-ports/m-p/982854#M919002</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-06-03T23:42:07Z</dc:date>
    </item>
  </channel>
</rss>

