01-17-2018 02:43 AM - edited 02-21-2020 07:09 AM
hi all,
i have one cisco 5506-x purchased with firepower and i want to introduce to my network without any changes. i have cisco 2901 router with 2 vlans sub interfaces in dot1q interfaces. now i want to connect asa as transparent mode. my question is will the asa pass both the vlans or not. if yes how we can achieve that because in transparent mode i can assign only one IP to the ASA.
thanks
cyril
01-17-2018 03:29 AM
you might want to check this post https://supportforums.cisco.com/t5/firewalling/cisco-asa-55xx-transparent-mode-vlan-traversing/td-p/2528610
01-17-2018 10:03 AM
The original poster asks how to implement ASA in transparent mode when there are two vlans and he has only a single IP address. This implies that he believes that he will configure an interface for each vlan and assign an IP address to each interface. But that is not the case. In transparent mode the IP address is used only for management traffic and does not have any role about inspecting traffic.
HTH
Rick
01-21-2018 07:07 PM
01-22-2018 08:32 AM
Cyril
Yes the router interface connects to ASA interface, other ASA interface connects to switch when ASA is configured for transparent mode. All traffic, tagged and untagged, passes through the ASA and is inspected. The IP address on the ASA is used only for management to and from the ASA.
HTH
Rick
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide