Cisco ASA 5505 VPN Access with separate VLANS inside

Posted on 2009-02-18
Last Modified: 2012-05-06
I am currently tasked with the job of settings up a remote access solution to some PLC OEM equipment in a factory.  There are currently two lines setups with different subnets in each line.

Line 1: /
Line2: /

Each line has its own dedicated switch and is physically disjoined in the network.
The OEM equipment uses multicast to communicate with one another, so IGMP port snooping must be enabled on the switches.

They soon will add another Line to the mix with an undetermined IP scheme.  They want all three lines to be unable to communicate with each other, but they do want to access all three lines using a VPN for remote access and eventually down the road to have all three lines be able to talk to a data collecting server.

Short term they are in urgent need of remote access to the two lines currently in operation.  My quick setup would be to install a Cisco ASA 5505 with an unlimited license.  From what I understand, it supports 3 VLANS out of the box (1 Internet, 2 Work, 3 Home).  It doesnt not support more than 3 VLANS and doesnt not support VLAN trunking unless you buy the Security Plus license.  AND it doesnt support IGMP port snooping.

I wanted to setup VLAN 1 with an IP of / & VLAN 2 with / & of course VLAN 0 would be the internet.

From my understanding, both networks will be able to communicate with the internet, but not each other since they are on separate VLANS, BUT once I VPN into the Cisco ASA remotely, how am I suppose to access BOTH networks?  Do I setup two different VPN policies in the ASA?  Is this even possible?  I thought for sure it would have to be.  Please forgive me, I am not a Cisco expert by any means.

The long term goal is to change the subnet of each line to so that ALL the OEM equipment is on the same subnet.   Plug each line into a Cisco switch that does support VLANS and IGMP Port Snooping, then VLAN off each Line to its own port and setup a VLAN trunk to the Cisco ASA.

Does the Cisco ASA have to support VLAN trunking to do this, or just the switch?  The reason I ask, is I have to know if I need to buy the Security Plus license.

I am looking for any tips, tricks, or suggestions.  Thank you in advance.
Question by:tyty4u2
    LVL 5

    Expert Comment

    out of the box asa5505 supports 3 VLAN.
    1. external (untrusted) with sec level 0
    2. internal (trusted) on sec level 100
    3. DMZ (restricted) sec level higher then 0 but less then 100

    while setup you have to decide from where DMZ shoul be accessible. cause of the restrictions you cant connect dmz to inside AND outside.

    you can setup vpn to access both DMZ and inside while using one tunnel. it depends on your traffic selection and your translation exemptions.

    Author Comment

    So I can put Line 1 on the Trusted network and Line 2 on the DMZ.  Setup a VPN that will allow access to both even though they are on different subnets?
    LVL 5

    Accepted Solution

    yes you can. add both subnets to traffic-selection of vpn. then you can see both subnets at the same time.

    Featured Post

    Why You Should Analyze Threat Actor TTPs

    After years of analyzing threat actor behavior, it’s become clear that at any given time there are specific tactics, techniques, and procedures (TTPs) that are particularly prevalent. By analyzing and understanding these TTPs, you can dramatically enhance your security program.

    Join & Write a Comment

    Overview The Cisco PIX 501, PIX 506e, ASA 5505 and ASA 5510 (most if not all of this information will be relevant to the PIX 515e but I do not have a working configuration handy to verify the validity) are primarily used within small to medium busi…
    Juniper VPN devices are a popular alternative to using Cisco products. Last year I needed to set up an international site-to-site VPN over the Internet, but the client had high security requirements -- FIPS 140. What and Why of FIPS 140 Federa…
    After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
    After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

    733 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    17 Experts available now in Live!

    Get 1:1 Help Now