cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
784
Views
0
Helpful
3
Replies

Cisco asa multiple active interfaces on one switch with no switch vlan configuration.

LC O
Level 1
Level 1

I was wondering if there is a workaround on cisco asa of having 2 vlan interfaces on one switch. The reason that i ask i have a cisco asa 5505 and a dell switch that doesn't support vlan configuration. I configured 2 vlan interface on cisco asa and when both interfaces are active my internet drops frequently. I was wondering if there is any such way to configure the cisco asa to make this thing to work. Thanks in advance...

1 Accepted Solution

Accepted Solutions

Assuming the Dell switch at least supports spanning tree, connecting multiple interfaces from the ASA to the Dell should result in all but one being put into spanning tree blocking state so as to avoid a spanning tree loop.

If the Dell does not support spanning tree then you would be in very bad shape as every broadcast packet would loop indefinitely and cause what we call a "broadcast storm".

One way does no good and the other does actual harm.  

View solution in original post

3 Replies 3

Marvin Rhoads
Hall of Fame
Hall of Fame

You can make it work by nor doing that. :)

If the Dell is a single VLAN-only switch then you should only connect ASA interfaces assigned to that VLAN.

If you have a single device (or just a couple) that you need to be on a second subnet then plug them directly into ports on the ASA assigned to that VLAN

so from my understanding i cant have 2 asa interfaces on a dell single switch i only have i cisco asa 5505 and 1 dell switch. just to let you know the dell switch is not a manageable switch. 

Assuming the Dell switch at least supports spanning tree, connecting multiple interfaces from the ASA to the Dell should result in all but one being put into spanning tree blocking state so as to avoid a spanning tree loop.

If the Dell does not support spanning tree then you would be in very bad shape as every broadcast packet would loop indefinitely and cause what we call a "broadcast storm".

One way does no good and the other does actual harm.  

Review Cisco Networking for a $25 gift card