11-19-2017 04:07 PM - edited 02-21-2020 06:46 AM
Hi,
We are in the process of carrying out the following:
A. Move our VLAN Layer 3 Virtual Gateways from our core switch to our Internal ASA Firewall. We will create sub-interfaces on the "Inside" interface for each VLAN and use that sub-interface as the Gateway for each VLAN.
I have a question around this:
1. Will IPS/IDS engine on Firepower be able to carry out inspection on traffic hitting each gateway on the sub-interfaces of the "Inside" interface?
Appreciate your assistance and advice.
Thanks,
Peni.
Solved! Go to Solution.
11-20-2017 12:05 AM
Actually, you are not configuring sub-interfaces on the "inside" interface, you are configuring them on a physical interface. Each sub-interface will become a firewall interface same as inside, outside and so on. With Modular Policy Framework (MPF) you control on which firewall-interface the traffic should get inspected by Firepower.
All in all, it will work what you want to do.
11-21-2017 02:40 PM
A: Yes
B: It depends. Very often, static routing is enough and a dynamic routing-protocol is not needed.
11-20-2017 12:05 AM
Actually, you are not configuring sub-interfaces on the "inside" interface, you are configuring them on a physical interface. Each sub-interface will become a firewall interface same as inside, outside and so on. With Modular Policy Framework (MPF) you control on which firewall-interface the traffic should get inspected by Firepower.
All in all, it will work what you want to do.
11-21-2017 02:37 PM
Bula Karen,
Thanks for the confirmation as per my question.
In addition:
A. Will we need to trunk the link between our core switch and ASA internal interface (which will contain the sub-interfaces) and allow valid VLAN's over this trunk?
B. Since, routing between the VLAN's will now be handled and inspected by ASA, i am guessing i will need to enable EIGRP on ASA firewall to do this?
Thanks for the advice so far.
Peni.
11-21-2017 02:40 PM
A: Yes
B: It depends. Very often, static routing is enough and a dynamic routing-protocol is not needed.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: