cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
867
Views
5
Helpful
7
Replies

Firewall Configuration

amro.shoufi
Level 1
Level 1

Hello all 

I have ASA Firewall 5555x but in the configuration i can't add an VLAV, the coand ia not available even Intervace VLan x is not working 

I tired also to.switch the firewall to Transparant mode but the same happened 

Please urgent help 

1 Accepted Solution

Accepted Solutions

The -X ASAs don't use VLAN interfaces. These are only used on the 5505. You have to configure subinterfaces to have  VLANs on a given physical interface.

View solution in original post

7 Replies 7

enunez147
Level 1
Level 1

Hello,

can you show me the licensing of the ASA and the IOS? I think that there is a problem with them.

regards

Erick

Hello Erik,

  • I am not using any license its stock,  It's ASA 9.6.1 - Device is 5555-x which is part of 5500-x series

The -X ASAs don't use VLAN interfaces. These are only used on the 5505. You have to configure subinterfaces to have  VLANs on a given physical interface.

Thank u karsten ,

I think u are right, i tried to much but there is no way, do u know any alternative way to do it mymain issue i want to create imterface that all users whom connect through any physical interface to get the access to it , i dont want to use switch the firewall has 8 ports it's enough.

So you want to attach your users directly to the ASA as it was common on the 5505?

No, that's not possible. But I'm happy to trade in one of my 5505s against your 5555-X. Will be a Win-Win for both of us. ;-) 

Ok, no kidding any more. Get any small switch and connect it to your ASA-interface. That's the only way to go.

Hello karsten,

Okay lets trade :)

I dont know if u know about below issue :

Current i connect the firewall directly to ISP by this Digram :

Outside interface : point to point between router and ISP MPLS 

Inside interface : assign it a Public IP 

Default route : outside 0.0.0.0 0.0.0.0 MPLS point to point 

This cenario was working with the cisco router but now its not working with ASA i can reach point to point from ISP MPLS but i cant reach the Public IP's also from the router if i do trace the traffic ia not going to the MPLS interface is any thing i need to add ?

Not sure if I understand you correctly ...

  • You are outside and want to access/ping the ASA inside interface
  • You are inside and want to access/ping the ASA outside interface

That doesn't work on the ASA by design. Nothing to configure or add.