04-07-2020 02:11 PM
I have a Cisco 5506-x (5 VLAN limit) and a Catalyst 2960-CG. I want to create about 15 VLANS. I was wondering if i could just create these on the Catalyst 2960-CG and not create them on the ASA or would I need to create them on both and have more VLAN capacity on the ASA?
04-07-2020 02:41 PM - edited 04-07-2020 02:49 PM
Hi,
VLANs do not need to be defined on the ASA, assuming the switch supports inter-vlan routing (which I believe the 2960CG does) you can configure the VLANs on the switch. The IP address assigned to each VLAN would be the default gateway for clients in each VLAN. The link between the switch and the ASA could be a dedicated VLAN on the switch, doesn't need to be trunked. You would require a static route on the switch for the default route (0.0.0.0/0.0.0.0) pointing to the ASA's inside IP address. The ASA would require static routes pointing to the switch for each of the VLAN networks. Or setup a dynamic routing protocol, only OSPF and RIP appear to be supported on that model.
HTH
04-07-2020 08:03 PM
04-08-2020 03:03 AM
No, you don't need to trunk (you said the ASA doesn't support that many VLANs). Just create a routed link between the ASA and the switch, use static routes or run a routing protocol.
04-08-2020 03:09 AM - edited 04-08-2020 03:11 AM
Cisco ASA doesn't support VTP, so I would recommend against using VLAN Switching function in the ASA integrated switch except as a last-resort option.
Good luck trying to maintain the VLAN database between your Layer2 catalyst switching fabric and your ASAs.
https://community.cisco.com/t5/switching/asa-5520-vtp-mode/td-p/1098591
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide