02-13-2013 09:05 AM - edited 03-11-2019 06:00 PM
This is for an ASA 5505 with the base license...
I have a situation where I will not have one interface in my outside VLAN, but instead I want to have interfaces 1-7 in my outside VLAN and interface0/0 in my inside VLAN.
Is this supported with the Base license, and if so how would I do this? Do I still just need to assign one IP address to the outside VLAN?
Or will I need to upgrade to the Security Plus license and put each interface in a separate outside VLAN, so in essence I would have 7 outside VLANs each with the same security level (0)?
My situation is that I have several partner networks that i want to "aggregate" thru my one ASA 5505. So each outside interface represents a separate partner (outside) network, each of which I want to get to from my inside network. Hence the many outside to one inside.
Thanks in advance and appreciate any help.
02-13-2013 09:20 AM
Hi,
I guess the question is how are you planning on connection all those Partner Networks to the ASA? I'm not sure if I get the whole picture here.
Is there a completely separate physical connection coming from all the Partner Networks to your site and at your site you want to gather all the connections to the ASA forward all the traffic through the ASA5505 before entering your local network?
Or are you planning on some kind of L2L VPN setup or what?
- Jouni
02-13-2013 12:00 PM
JouniForss wrote:
Is there a completely separate physical connection coming from all the Partner Networks to your site and at your site you want to gather all the connections to the ASA forward all the traffic through the ASA5505 before entering your local network?
- Jouni
Yes - this is my intent. Essentially I am bringing in many "outside" connections into one "inside" connection. All connections will be initiated from the inside.
02-13-2013 12:23 PM
Hi,
Heres what I am assuming
I guess in this case it might even be possible to use Base License (are we talking about a 10 user limit when checking the "show version" output?)
You could try to
I'm kinda wondering also that IF you have 10 user license then you will probably need to configure a default route pointing somewhere on the "outside" since the host behind the interface with the default route wont be counted towards the user limit.
Heres one discussion from these forums that clarifies the above a bit
https://supportforums.cisco.com/thread/2144579
There should also be Cisco document about the ASA5505 models user limits.
- Jouni
02-13-2013 01:06 PM
JouniForss wrote:
Hi,
Heres what I am assuming
I guess in this case it might even be possible to use Base License (are we talking about a 10 user limit when checking the "show version" output?)
You could try to
I'm kinda wondering also that IF you have 10 user license then you will probably need to configure a default route pointing somewhere on the "outside" since the host behind the interface with the default route wont be counted towards the user limit.
Heres one discussion from these forums that clarifies the above a bit
https://supportforums.cisco.com/thread/2144579
There should also be Cisco document about the ASA5505 models user limits.
- Jouni
Jouni - thanks for your time!
To answer your questions:
1. all your assumptions are correct
2. For each physical connection, there would be one long running TCP session - so there would be 7 connections per ASA, originating from an inside server to one host on each of the partner networks.
3. On all the route configurations you mention that is what I intended.
My resulting question is this:
How would I configure NAT in this instance?
02-13-2013 01:24 PM
Hi,
The NAT configuration depends on your ASA software. It might even be that you would not need to configure ANY NAT at all
I actually didnt think one of the things through and that is that you would actually have 2 options how to handle the routing between the Partner Network routers and your "inside" network.
EDIT: Heres a link to the ASA 8.2 software Command Reference and the command "nat-control"
http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/no.html#wp1746857
Hopefully I made any sense and the information was helpfull
- Jouni
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide