A friend of mine runs a small VPS hosting company and has a few servers in a remote DC. He had purchased an ASA 5512-X and intends to use it to monitor traffic transparently between his servers and the uplink to his DC Internet connection.
I helped him setup the ASA in his home lab and we have transparent mode working with a single subnet. However his DC has provisioned five unique IP subnets for external connectivity on a single VLAN. He has a single 1 Gbps connection.
Is there anyway to make this work with the ASA? My understanding is there needs to be a BVI interface on each L3 segment to make this work. I don't believe you can assign multiple IP addresses to a single BVI interface.
My suggestion to him was to talk to the provider and see if they can convert the link to a trunk and provision each external subnet on a different VLAN and then we could use subinterfaces on the ASA.
Connectivity flow is (Single 1 Gbps Internet feed from DC) > L2 VLAN on a Switch > ASA > L2 VLAN on Switch > Servers
There is a no NAT involved.
... View more
Hi J, Are you still having this issue? We have almost exactly the same setup as you except with a V10000 appliance and see the same symptons you see. Our N7K's are running 6.1(4a). We have been having a horrid time getting help from Websense who is trying to push the blame on the Nexus side. If we solve this problem I will post an update in case anyone else can benefit. Thanks, Andrew
... View more