cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
840
Views
1
Helpful
10
Replies

ASA 5525-New created sub-interface is not showing up in firewall area

Awacs2000
Level 1
Level 1

My customer has a ASA 5525 with version 9.14(4)7 and ASDM 7.18(1)152
He created a new VLAN-sub-interface below his port-channel6. So far so good.
But when he wants to create rules for this new vlan, the section is missing in the firewall configuration-area.
Total sub-interfaces on this port-channel are 39 currently.
I rebooted the cluster and updated ASDM, but this this not help

Any ideas?

10 Replies 10

Vlan and subinterface? One of them must use not both.

Can i see the config 

MHM

Awacs2000
Level 1
Level 1

This is the config. All other subinterfaces are OK and they are able to create rules for them in the firewall area.

Awacs2000_0-1706777745947.png

Awacs2000_1-1706777826248.png

 

Awacs2000
Level 1
Level 1

Ping to the Interface is possible

this connect to SW in trunk and you allow VLAN 771?
MHM

ASA 5525 base license can have up to 200 vlan (not per port but per asa "global")

So if you have subinterface with vlan more than 200 you face license issue' to make sure shut one unused subinterface and check this new one are it appear or not.

If you have less than 200 then check vlan allow in trunk in SW

MHM

Awacs2000
Level 1
Level 1

I checkes withe the customer and the VLAN is configured on the switch and on the trunk towards the ASAs.
Strange thing.

Then last thing check number of vlan is it more than 200 it can license issue.

MHM

Awacs2000
Level 1
Level 1

No, the number of VLANs is below 200. Not even 100.

Awacs2000
Level 1
Level 1

I think I solved it. Simple thing. I just said "Add Access rule" and voilá there it was in the dropdown-menu.

glad issue is simple and solved 
have a nice day friend 

MHM

Review Cisco Networking for a $25 gift card