Showing results for 
Search instead for 
Did you mean: 


How to Configure Secondary IP on inside interface of ASA 5520

Hi, We already have a subnet defined to inside interface and is in produciton. the default gateway is this interface ip. In that setup now I have to add one more subnet and as the first subnet is been defined in ASA indside interface, I have to assign secondary Ip to the inside interface so that new subnet users can easily reach here and go outside.

MY ASA is not internet facing but is facing my private MPLS cloud.

Kindly advice

Jouni Forss


I have run into situation where this would have been usefull but I have always gone with a different setup and not configured any secondary networks under one interface.

If you are indeed configuring another subnet under the same LAN interface I guess you can do it a few commands. I'm not sure if theres been some changes to the ASA software that might cause problems.

To my understanding the configuration used to be like this

  • Existing subnet:
  • ASA Interface IP:

  • New subnet:
  • ASA Interface IP:


  • arp inside 1234.5678.90ab alias
  • route inside
  • same-security-traffic permit intra-interface

I would expect this has limitations but I can't say for sure as I have never resorted to it myself. It might not even work anymore depending on your software. I would suggest looking at the whole network setup, perhaps handling this with a real router instead of ASA. Perhaps configuring a Trunk between ASA and some LAN Switch and creating a separate ASA interface for both subnets.

But this is just my personal suggestion. I always try to keep things simple and avoid special setups. In the long run you might either be causing a bigger headache for yourself or just end up doing the change which would have been best in the first place

- Jouni

IOS 9.2(3)4

Invalid next hop address, it matches our IP address.

Content for Community-Ad