cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3517
Views
0
Helpful
4
Replies

Private VLAN and ASA subinterfaces

seegomaa
Level 1
Level 1

Gents,

I have a dmz 3750 switch and i want to introduce private VLAN on this switch. This switch is connected to cisco ASA with trunk (subinterface for each primary VLAN) because we have multiple dmz. How the configuration on both sides will be ?.

If private VLANs can't be used with ASA subinterfaces, what  solution can be done in this scanario ?

Thanks,

4 Replies 4

IAN WHITMORE
Level 4
Level 4

I would think the ASA doesn't care. The Pvlans are configured on the switch. The port that the ASA is connected too will be promiscuous.

To see how to configure it, check out this guide (a long in depth read but worth it):

http://www.cisco.com/en/US/docs/switches/lan/catalyst4500/12.2/31sga/configuration/guide/pvlans.html

Regards,

Ian

If I hepled please rate me.

Thank you for your reply,

But The connection between the switch and ASA  is a trunk and not an access port

That shouldn't make any difference. You just need to make sure you permit the Pvlans on the trunk. Here is a doc on this...although its for the 4500 should be able to apply the throty.

http://www.cisco.com/en/US/docs/switches/lan/catalyst4500/12.2/31sga/configuration/guide/pvlans.html#wp1166138

Regards,
Ian

evazquez3
Level 1
Level 1

I don't think this is supported on 3750.  Or did you find that it was?