<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA questions in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-questions/m-p/849652#M956956</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a setup with 1 ASA5520 with 4 interfaces. I need to connect 2 core switches (Cat65xx) to two of the interfaces, while another 2 interfaces goes to the internet router and the dmz respectively. The core switches are running in a redundant topology setup, and the 2 links to the firewall are supposed to be running simultaneously (ASA running in routed mode, the 2 internal links are routed links). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is:&lt;/P&gt;&lt;P&gt;Can i use 1 of the network port on the ASA and set it up as a trunked link with 2-3 vlans? All the hosts in those vlans will be forced to use the ASA as its default gateway. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;w&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 11:48:47 GMT</pubDate>
    <dc:creator>wkw</dc:creator>
    <dc:date>2019-03-11T11:48:47Z</dc:date>
    <item>
      <title>ASA questions</title>
      <link>https://community.cisco.com/t5/network-security/asa-questions/m-p/849652#M956956</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a setup with 1 ASA5520 with 4 interfaces. I need to connect 2 core switches (Cat65xx) to two of the interfaces, while another 2 interfaces goes to the internet router and the dmz respectively. The core switches are running in a redundant topology setup, and the 2 links to the firewall are supposed to be running simultaneously (ASA running in routed mode, the 2 internal links are routed links). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is:&lt;/P&gt;&lt;P&gt;Can i use 1 of the network port on the ASA and set it up as a trunked link with 2-3 vlans? All the hosts in those vlans will be forced to use the ASA as its default gateway. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;w&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:48:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-questions/m-p/849652#M956956</guid>
      <dc:creator>wkw</dc:creator>
      <dc:date>2019-03-11T11:48:47Z</dc:date>
    </item>
    <item>
      <title>Re: ASA questions</title>
      <link>https://community.cisco.com/t5/network-security/asa-questions/m-p/849653#M956958</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you can create subinterfaces on the ASA as follows:&lt;/P&gt;&lt;P&gt;int eth0/2&lt;/P&gt;&lt;P&gt;  no shut&lt;/P&gt;&lt;P&gt;int eth0/2.100&lt;/P&gt;&lt;P&gt;  vlan 100&lt;/P&gt;&lt;P&gt;int eth0/2.200&lt;/P&gt;&lt;P&gt;  vlan 200&lt;/P&gt;&lt;P&gt;int eth0/2.300&lt;/P&gt;&lt;P&gt;  vlan 300&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;....&lt;/P&gt;&lt;P&gt;that's just an example.  the subinterface number does not have to be the same as the vlan, but it helps making the config more readable.&lt;/P&gt;&lt;P&gt;It will then use dot1q on this connection for VLAN tagging.  the physical interface (in this case, eth0/2) passes untagged traffic, only if you apply the nameif command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/intrface.html" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/intrface.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;..for more details&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jan 2008 04:57:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-questions/m-p/849653#M956958</guid>
      <dc:creator>srue</dc:creator>
      <dc:date>2008-01-16T04:57:43Z</dc:date>
    </item>
  </channel>
</rss>

