09-22-2012 01:18 AM - edited 03-11-2019 04:57 PM
Hello,
I know cisco asa can do virtualization with virtual context.
My question is as far as i know if i create perhaps 3 virtual context web, app, and db logicaly it in the same layer, only 1 layer.
Can i create layered virtual context?. So if physically my asa interface only connect to 1 port switch but logically will look like this :
Firewall
|||||
Web context
|||||
App Context
|||||
Db context
09-27-2012 07:14 AM
Ibrahim,
Yes you can share the same phusical interface with between context. You actually have 2 options:
1. create subinterfaces and assign a different subinterface to each context.
2. Assign the physical interace to the 3 contexts but "mac-address auto" must be enable to avoid packet classyfication issues.
Luis
10-11-2012 12:56 AM
Yes i already know about virtual context or sub interface. When i do virtual context or sub interface, the topology will be like this :
Firewall
|| || ||
Contex1 Contex2 Contex3
Btw:another question can i do vrf lite from core switch to firewall/virtual context?
what i want is, this is not my req just an idea.
Firewall
||
Contex1
||
Contex2
||
Contex3
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide