02-27-2009 04:53 AM - edited 03-11-2019 07:58 AM
I am looking at moving two physical interfaces ( inside,dmz ) to a dot1q trunk on the same firewall.
How would you go ahead to minimize impact on the running configuration?
To my understanding you have to remove "nameif inside" from the physical interface and move this command to the subinterface instead ( eg int Ethernet0/2.10 ).
When removing the inside command I suppose I will lose all my statics and accesslists refering to "inside".
Is this the only way to do it ?
Solved! Go to Solution.
02-27-2009 07:42 AM
Mmmmmm if I were you - I would just move the DMZ. keep the inside interface on the physical port is it now, then just create a sub interface for the DMZ.
Then change the switch port the inside interfaces connects to from an access port to a trunk....that way if you can't get it working right away - you just need to change the switch port back to an access port with minumal disruption.
Or configure the native vlan command to the VLAN the inside interface is associated to, on the switch port - that way in access layer or trunk layer you will always get connectivity to the inside interface.
HTH>
02-27-2009 07:42 AM
Mmmmmm if I were you - I would just move the DMZ. keep the inside interface on the physical port is it now, then just create a sub interface for the DMZ.
Then change the switch port the inside interfaces connects to from an access port to a trunk....that way if you can't get it working right away - you just need to change the switch port back to an access port with minumal disruption.
Or configure the native vlan command to the VLAN the inside interface is associated to, on the switch port - that way in access layer or trunk layer you will always get connectivity to the inside interface.
HTH>
02-28-2009 03:14 AM
Yup...that worked out fine - good point !
02-28-2009 03:48 AM
np - glad to help.
Thanks for the rating.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide