01-29-2020 03:27 PM
Hi All,
I am trying to figure out if we can multiple security zones on same etherchannel.
For example: inside & DMZ
We have 8 ports on the ASA(standalone) and was thinking to create either one of following.
1- create 2 ports etherchannel for Inside zone and 2 port etherchannel for DMZ, keeping inside zone and DMZ separate.
I will have to create multiple subinterfaces for multiple vlans such as user,voip,server.
example for INSIDE port channel:
Interface Port-channel 1.1
vlan 10
nameif user
security-level 100
ip address x.x.x.x x.x.x.x.x
Interface Port-channel 1.2
vlan 20
nameif Server
security-level 100
ip address x.x.x.x x.x.x.x.x
Similarly for port-channel 2 (DMZ) I will have to create multiple subinterfaces for multiple vlans such as DMZ, wireless etc
Interface Port-channel 2.1
vlan 30
nameif DMZ
security-level 50
ip address x.x.x.x x.x.x.x.x
Interface Port-channel 2.2
vlan 40
nameif wireless
security-level 100
ip address x.x.x.x x.x.x.x.x
2 - I can bundle up 4 physical ports into one port-channel and combine INSIDE and DMZ all in same port channel.
Example:
Interface Port-channel 1.1
vlan 10
nameif user
security-level 100
ip address x.x.x.x x.x.x.x.x
Interface Port-channel 1.2
vlan 30
nameif DMZ
security-level 50
ip address x.x.x.x x.x.x.x.x
is it a best practice or should I keep the Zones in separate port-channels ? or keeping all in one port-channel ? any security concerns ?
Also we will be connecting additional firewall later infront of ASA 5525-X and that additional firewall will only be used for S2S VPN connections.
Solved! Go to Solution.
01-29-2020 03:36 PM
01-29-2020 03:36 PM
01-29-2020 03:42 PM
Good Point Francesco.
do all dmz and users vlans are located on the same switch? Yes, there is down stream stack of 2 member switches, All VLANs will reside on it.
However if you want to have a big PO to increase the max bandwidth ? My understanding is even if bundle four physical ports in one etherchannel, I think (or maybe mistaken) the throughput will remain 2Gbps as a limitation on ASA5525-X ?
01-29-2020 03:50 PM
01-29-2020 04:02 PM
Great.. Much appreciated for your prompt responses.
01-29-2020 07:02 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide