09-09-2018 07:32 PM - edited 02-21-2020 08:13 AM
I have the need to harden 3 legacy servers and the ASA-5505 was picked for the solution. I want to start by allowing traffic pass and then add ACL's to gradually increase the security. The ASA will be in the middle of the network, that is why I like transparent mode. looking at he notes my issue may be that 1 of the 3 servers is on a different subnet. I have set up a basic configuration of the outside interface being 0, and inside at 100.
Since transparent is like a bump on the wire will both subnets still pass through the ASA ?
Solved! Go to Solution.
09-09-2018 08:32 PM
09-10-2018 09:30 AM
09-09-2018 07:45 PM
Hello,
ASA supports only traffic for one subnet and this subnet is the same as defined for the management interface subnet. You can create bridge group for each subnet you have defined, more info in the link:
HTH
AJ
09-09-2018 08:32 PM
09-10-2018 12:10 AM
09-10-2018 07:14 AM
That is a great point. The 3 servers are isolated, so I don't want them to have access to each other anyway. I just wondered if the BVI's would just send them out the gateway as the last hop does now. The firewall is being added to an existing working solution, we just want to limit the traffic in/out. I tried packet tracer to troubleshoot this but the firmware (even the latest) doesn't support BVI.
I don't have enough hardware to sandbox this, and don't want to try it in production. The one server that has a different subnet gets out now, but will it in transparent mode ?
Thanks for the look.
09-10-2018 09:30 AM
09-10-2018 06:41 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide