cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
341
Views
0
Helpful
2
Replies

Firewall Vlan Design question

mahesh18
Level 6
Level 6

 

Hi Everyone,

 

Is this setup ok

ASA1 and ASA2 are on different networks and vlan 2 is for management only on ASA2 and switch.

In order to access the ASA2 and switch via vlan 2 i configured vlan 2 also on ASA1.

ASA1-----vlan2------int1  -------------vlan2-----int1 ------ASA2------int2---trunk int including vlan 2--------vlan2-----switch

Say ASA1 vlan int has IP 192.168.50.1

ASA2-----vlan int1 IP 192.168.50.2

ASA2 trunk interface 2 IP 192.168.50.3

 

Is this normal network design to have two interfaces on ASA with IP address on same subnet?

Regards

MAhesh

1 Accepted Solution

Accepted Solutions

Jon Marshall
Hall of Fame
Hall of Fame

Mahesh

Is this normal network design to have two interfaces on ASA with IP address on same subnet?

This would only work if the ASA was in transparent (L2) mode and then you wouldn't actually assign IPs to the interfaces.

If this is in routed (L3) mode which I suspect it is then you can't do this ie. have the same IP subnet on either side of the ASA.

Jon

View solution in original post

2 Replies 2

Jon Marshall
Hall of Fame
Hall of Fame

Mahesh

Is this normal network design to have two interfaces on ASA with IP address on same subnet?

This would only work if the ASA was in transparent (L2) mode and then you wouldn't actually assign IPs to the interfaces.

If this is in routed (L3) mode which I suspect it is then you can't do this ie. have the same IP subnet on either side of the ASA.

Jon

 

Many thanks Jon.

Review Cisco Networking for a $25 gift card