[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

How would you create a vlan on a cisco catalyst 3500 connect to Cisco asa 5500.

Posted on 2009-04-17
6
Medium Priority
?
949 Views
Last Modified: 2012-06-27
How would you create a vlan on a cisco catalyst 3550 switch connect to Cisco asa 5500 firewall.
 
 
0
Comment
Question by:henjohn1520
  • 3
  • 2
6 Comments
 
LVL 4

Accepted Solution

by:
jordanrog earned 2000 total points
ID: 24171269
here is how to do it. It is a step by step walk through if you get stuck just add a comment and I will do my best. The second link is for vtp.

http://www.cisco.com/en/US/tech/tk389/tk689/technologies_configuration_example09186a008009478e.shtml

http://www.cisco.com/en/US/tech/tk389/tk815/technologies_configuration_example09186a008015f17a.shtml#config1
0
 

Author Comment

by:henjohn1520
ID: 24173537
What changes would need to be done on the asa 5500 firewall? Would I have to create a vlan to match the new vlan on the switch? Let me explain how the Cisco 3550 switch is connected to the Cisco ASA 5500 firewall.

Port 0/23 on the Cisco 3550 switch is connected to port 0/1 on the Cisco ASA 5500 firewall. Port 0/23 is in the Cisco 3550s default vlan 1 and its set to switchport mode dynamic desirable. Port 0/1 is in the Cisco ASA 5500s vlan1. What would be the first step?
0
 
LVL 79

Expert Comment

by:lrmoore
ID: 24200995
You would create a trunk port between the switch and the ASA
On the switch:
 interface fast 0/23
  switch trunk encap dot1q
  switch mode trunk

Then, define a VLAN on the switch:
 vlan 123
exit
Then, assign an interface to this vlan
 interface fast 0/xx
  switch access vlan123

On the ASA, create a sub-interface for the new vlan, with vlan ID
interface Ethernet 0/0.123
 vlan 123
 nameif vlan123
 security-level 100
 ip address 192.168.123.1 255.255.255.0
0
New feature and membership benefit!

New feature! Upgrade and increase expert visibility of your issues with Priority Questions.

 

Author Comment

by:henjohn1520
ID: 24205638
Would anything need to be done to allow computers on the new vlan to access the internet.
0
 

Author Comment

by:henjohn1520
ID: 24207904
I am unble to create a sub-interface with my cisco asa 5505.  I followed the commands that you provided, but I was unable to.
0
 
LVL 79

Expert Comment

by:lrmoore
ID: 24207932
Ah.. 5505 is a little different
Here's a good piece from our friend batry_boy
http://www.experts-exchange.com/Hardware/Networking_Hardware/Firewalls/Q_22456080.html
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Arrow Electronics was searching for a KVM  (Keyboard/Video/Mouse) switch that could display on one single monitor the current status of all units being tested on the rack.
This article will show how Aten was able to supply easy management and control for Artear's video walls and wide range display configurations of their newsroom.
This Micro Tutorial will teach you how to add a cinematic look to any film or video out there. There are very few simple steps that you will follow to do so. This will be demonstrated using Adobe Premiere Pro CS6.
Are you ready to place your question in front of subject-matter experts for more timely responses? With the release of Priority Question, Premium Members, Team Accounts and Qualified Experts can now identify the emergent level of their issue, signal…
Suggested Courses

834 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question