Solved

How should I setup my switch attached to ASA 5510 to allow two VLANs in a trunk?

Posted on 2010-09-08
3
488 Views
Last Modified: 2012-05-10
I have an ASA 5510 firewall and I have used all 4 ethernet ports for different subnets. I need to VLAN some traffic from my internal network and terminate it on the inside interface (ethernet/1) using a virtual interface with a VLAN (for example ethernet0/1.192).

I have setup a vlan of ID 192 on the ports I need on my switches (they are either cisco 3550 or 3560 switches) and created the virtual interface ethernet0/1.192 on my ASA with the correct security level. It has an IP address and I have enabled DHCP on that interface. I have proved that VLANs are trunking between switches by plugging devices into the ports on vlan 192 and pinging them successfully then trying to ping an internal IP after changing my IP to that subnet and correctly being unable to do so.

I think my problem lies at the switch port that connects to ethernet0/1. Currently it is set to an 802.1q trunk (like the rest of the switches) but I cannot gain an IP via DHCP or even force myself onto the subnet of the IP associated with the virtual interface ethernet0/1.192 to ping it.

My question is, how do I setup my switch port (or ASA port, if that's where the problem lies) to allow the VLAN to hit the virtual interface? I'm at a total loss and seem to have hit a wall of knowledge. Thanks in advance.

Jon.
0
Comment
Question by:Keithburnham
  • 2
3 Comments
 
LVL 21

Accepted Solution

by:
from_exp earned 500 total points
ID: 33625374
hi!
please post here switch's and asa's config parts.
in general setup should look like this
imaging we are connecting gi0/0 of ASA to gi0/0 on 3560

asa:
interface GigabitEthernet0/0
no nameif
no security-level
no ip address
interface GigabitEthernet0/0.10
description towards_3560_vlan10
vlan 10
nameif vlan10if
security-level 0
ip address 10.1.10.1 255.255.255.0
!
interface GigabitEthernet0/0.20
description towards_3560_vlan20
vlan 20
nameif vlan20if
security-level 10
ip address 10.1.20.1 255.255.255.0
end

switch:
interface GigabitEthernet0/0
switchport trunk enc dot1q
switchport trunk allowed vlans 10,20
switchport mode trunk
end
0
 
LVL 1

Author Comment

by:Keithburnham
ID: 33625549
Sorry, it appears that I missed out physically adding the VLAN to the 3560 VLAN list. Reading your post remind me. Thanks for you help it all works just fine (4 phyisical interfaces all with IPs and a shared virtual interface on one of them).
0
 
LVL 1

Author Closing Comment

by:Keithburnham
ID: 33625565
The answer was correct but I had already set all of these settings in my configs. It did however lead me to then add VLAN 192 to the switch.
0

Featured Post

Portable, direct connect server access

The ATEN CV211 connects a laptop directly to any server allowing you instant access to perform data maintenance and local operations, for quick troubleshooting, updating, service and repair.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Cisco ASA 5512 LAN Config 16 77
Cisco IP Phone upgrade 3 35
CCNA lab 6 42
Ceiling heights max for internal antennas - Cisco 3702i access points 6 13
Cisco Pix/ASA hairpinning The term, hairpinning, comes from the fact that the traffic comes from one source into a router or similar device, makes a U-turn, and goes back the same way it came. Visualize this and you will see something that looks …
For months I had no idea how to 'discover' the IP address of the other end of a link (without asking someone who knows), and it drove me batty. Think about it. You can't use Cisco Discovery Protocol (CDP) because it's not implemented on the ASAs.…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

789 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question