09-26-2015 04:18 PM - edited 03-05-2019 02:23 AM
hi everyone,
i have a switch (2960) which is configured with several virtual interfaces. i need to add routing ability to this switch. however when i enable routing, the switch sees all the interfaces i created as being directly connected. but i also need to have the traffic inspected as it enters any of the interfaces. i have an asa and i would like the switch to forward all the traffic to this asa where it gets inspected. is it possible to do this?
thanks
09-26-2015 06:00 PM
If you were to do the routing between subnets on your ASA and leave the switch as layer 2 then the ASA could inspect all the traffic. If you enable routing on the 2960 then I am not aware of a way to send all traffic to the ASA to be inspected.
HTH
Rick
09-27-2015 08:25 AM
thank you Richard.
09-28-2015 06:16 AM
Hello,
Can you put the default gateway for your vlans onto the ASA, remove the SVIs on the 2960, and route through the ASA?
09-28-2015 01:12 PM
i will give it a try. thanks.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide