Link to home
Start Free TrialLog in
Avatar of fox54
fox54

asked on

ASA5510 and VLAN interface

Hi,

I have a ASA5510 that have all the interfaces occupied but i need to add some more DMZ

If i dedicate an interface to the Ouside for Internet, can i have my LAN and one or two DMZ in the same interface and have access-list applied to it just like it would have been with physical interfacce ??

Thanks



ASKER CERTIFIED SOLUTION
Avatar of craigothy
craigothy

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of fox54
fox54

ASKER

For security reason. is it best to have a physical interface for outside, a physical interface to inside (the LAN and also native VLAN1) and have trunking on the other ports to allow multiple DMZ ?

Like
interface Ethernet0/0: Internet (security 0)
interface Ethernet0/1: LAN native VLAN1 security 100
interface Ethernet0/2.10 DMZ1 security 5
interface Ethernet0/2.20 DMZ2 security 10
interface Ethernet0/2.30 DMZ3 security 15

Also is there any security risk associated with this kind of setup ??





SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial