cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2662
Views
0
Helpful
6
Replies

ASA Transparent mode and same vlan

AK59
Level 1
Level 1

Helle everyone,

 

I'm actually having trouble with the implementation of a firewall in Transparent mode. 

 

I have the configuration below , a router is connected to another one within a /24 subnet. 

I need to implement a firewall without changing anything on the layer 3 configuration ( interfaces or routing)

 

 

Here is the situation 

Vlan 6 - 10.1.1.0/24

 

Router1 ( int vlan 6 - 10.1.1.1) <=====> Router2 ( int e0/0 - 10.1.1.2)

 

I see that if I want to implement a firewall in transparent mode, I need to create 2 vlan  for the same bridge-group. 

But, as I'm using vlan 6 as between Router1 and 2. 

What vlan should I use ? Will it be something like that the scheme below 

 

Router1 ( int vlan6 - 10.1.1.1) <===> (vlan 6 ) ASA (vlan ?) <===> Router2 (int e0/0 10.1.1.2)  

6 Replies 6

It's pretty straightforward, just use VLAN 7 or any other number. Think
about it as access port, i.e. the vlan tag is not carried.

**** please remember to rate useful posts

AK59
Level 1
Level 1

Ok 

But, for example, if the router2 uses its "int vlan 6" interface, it would mean that i wall have traffic going from " int vlan 7 " in the ASA  going to "int vlan 6" on router 2. 

 

Both interfaces set in access mode, I will have untagged traffic so it will work, right ? 

 

If so, it means that just the naming would be incoherent right 

They don't need to be in same VLAN as its access. So if ASA in vlan 7 and
your router in vlan 6, it will still work as you aren't adding dot1q header
to the packets.

**** please remember to rate useful posts

ASA Bridged the VLAN, just deploy as suggest and test it.

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

ASA have two interface or Sub interface.
one connect to R1 and other connect to R2.
so ASA will receive the frame from R1 with VLAN ID =6 make the checking and then change the VLAN-ID to VLAN 7 and resend to R2.
there is no problem. 

Review Cisco Networking for a $25 gift card