11-12-2014 01:21 AM - edited 03-11-2019 10:04 PM
Hello,
I am working for translate firewall from to ASA now. As I know ASA did not support secondary interface IP.
However, my existing firewall setup is using this method to bind different subnet into single Interface.
Did any best practices to migrate into ASA environment?
Thanks!
11-12-2014 01:34 AM
Hi,
This depends on your current environment which we dont know about.
As ASA firewalls can not have secondary IP addresses on a single interface then the typical options would be to either
I guess it would also be possible to have 2 separate physical ASA interfaces connected to the same network switch network (Vlan) where the 2 subnet are used and just configure the other gateway on the other interface and the other subnet on the other physical interface. I would assume it could work but I am really hesitant to even write this as this would certainly be something that I would not even consider unless in some really urgent situation where there was no other options (for some reason).
- Jouni
11-12-2014 07:38 PM
Hi,
Thanks for comment. It looks very hard for me as too many subnets together, so using different ASA interface must not enough to allocate.
I just have dummy L2 switch, so it also hardly to re-locate the gateway at switch level.
I read some material about workaround using ARP proxy. Like following
http://www.ducea.com/2008/05/31/adding-a-secondary-ip-address-on-a-cisco-asa-ethernet-interface/
Is it possible?
Thanks!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide