Solved

Cisco VLAN trunk ASA5510 to Catalyst 3550.

Posted on 2008-06-13
5
10,104 Views
Last Modified: 2012-08-13
I am working on a project where an ASA5510 needs to be configured with multiple VLANs on a single physical interface. This has been configured using the sub interfaces with no issue. The port is then being connected to a Catalyst 3550. The switchport on the 3550 has been set to trunk mode using dot1q encapsulation. For some reason I cannot get any traffic to pass between the devices over any VLAN.

Any help is appreciated.


ASA5510 config:
 

!

interface Ethernet0/1

 description Physical DMZ Interface.

 no nameif

 no security-level

 no ip address

!

interface Ethernet0/1.1

 description External Wireless DMZ

 vlan 8

 nameif dmz-wireless

 security-level 10

 ip address 172.17.8.1 255.255.255.0

!

interface Ethernet0/1.2

 description Remote Access DMZ

 vlan 9

 nameif dmz-ra

 security-level 75

 ip address 172.17.9.1 255.255.255.0

!

interface Ethernet0/1.3

 description External Server DMZ

 vlan 10

 nameif dmz-server

 security-level 50

 ip address 172.17.10.1 255.255.255.0

!
 
 

Catalyst 3550 Config:
 

!

interface GigabitEthernet0/3

 description Connection to ma-fw-01 for DMZ VLANs

 switchport trunk encapsulation dot1q

 switchport trunk native vlan 10

 switchport mode trunk

 no ip address

 snmp trap link-status

!

Open in new window

0
Comment
Question by:jmproulx
  • 2
5 Comments
 
LVL 5

Expert Comment

by:Jinx_IT
ID: 21784279
My thoughts,

I wouldnt use sub interfaces on the ASA, I'd do something like the following

on the ASA setup all your Vlans as interfaces, and then set your for E0/1 as a trunk..for example...

Interface Vlan 10
 description **********
 nameif dmz-server
 security-level 50
 ip address 172.17.10.1 255.255.255.0

Interface Ethernet0/1
 switchport trunk encapsulation dot1q
 switchport trunk allowed vlan 8,9,10
 switchport mode trunk

I would also change the 3550

interface GigabitEthernet0/3
 description Connection to ma-fw-01 for DMZ VLANs
 switchport trunk encapsulation dot1q
 switchport trunk native vlan 10
 switchport trunk allowed vlan 8,9,10
 switchport mode trunk
 no ip address
 snmp trap link-status




0
 
LVL 7

Expert Comment

by:kanlue
ID: 21784545
while looking into this issue, i found the following link in EE that will give you some good idea:
-------------
Cisco ASA 5520 traffic to subinterface not working
http://www.experts-exchange.com/Hardware/Networking_Hardware/Routers/Q_22414323.html
-------------
please check it out.

hope it helps.


0
 

Accepted Solution

by:
jmproulx earned 0 total points
ID: 21835749
Well after a few different attempts at getting this to work, I realized that it may be an issue with the IOS version. After upgrading the IOS on the Catalyst 3550 to a new version the original configuration worked like a charm. Originally the IOS was an older version of the 12.1 tree, the updated version I moved to was a newer version in the 12.2 tree.

Thanks for the help and suggestions.
0
 
LVL 7

Expert Comment

by:kanlue
ID: 21835761
thanks for the update.
0

Featured Post

What Should I Do With This Threat Intelligence?

Are you wondering if you actually need threat intelligence? The answer is yes. We explain the basics for creating useful threat intelligence.

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
sync conflicts 1 26
Quick cusco 2091 setup 5 21
OSPF Cost 2 12
Allowing Multicast in the firewall 2 5
#Citrix #Citrix Netscaler #HTTP Compression #Load Balance
Meet the world's only “Transparent Cloud™” from Superb Internet Corporation. Now, you can experience firsthand a cloud platform that consistently outperforms Amazon Web Services (AWS), IBM’s Softlayer, and Microsoft’s Azure when it comes to CPU and …
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now