[2 days left] What’s wrong with your cloud strategy? Learn why multicloud solutions matter with Nimble Storage.Register Now

x
?
Solved

Cisco ASA 5510 VLAN Setup

Posted on 2011-03-15
3
Medium Priority
?
1,098 Views
Last Modified: 2012-05-11
This is going to be a drawn out question and probably will take some time for me to confirm the correct solution due to time restraints.

Regardless, I originally setup my Cisco ASA 5510's interfaces like this:

interface Ethernet0/1
 description inside
 nameif inside
 security-level 100
 ip address 192.168.10.1 255.255.255.0
 ospf cost 10
!
interface Ethernet0/2
 description inside2
 nameif inside2
 security-level 100
 ddns update hostname 192.168.10.26
 ddns update DNS_Update
 dhcp client update dns server both
 ip address 192.168.11.1 255.255.255.0
 ospf cost 10
!
interface Ethernet0/3
 description dmz
 nameif dmz
 security-level 50
 ip address 192.168.19.1 255.255.255.0
 ospf cost 10
!

I want to setup VLANS to make my network more efficient so I can take advantage of my gigabyte switches. My question is, if I move/make interface "inside2" to a sub interface (VLAN) under interface Ethernet0/1 (inside) will all my code in the firewall config be deleted or will all that remain in place if I name the new VLAN inside2 just like it was on interface Ethernet0/2 ?
0
Comment
Question by:jhakie
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 

Expert Comment

by:Bardlebee
ID: 35140274
When you state "code" I assume you mean ACL's? I have limited experience with ASA Firewalls, but I can tell you ACL's just sorta sit there waiting to be assigned to things. I dare say if you made a subinterface and assigned inside2 to it as well both interfaces would use those ACL's.

Worse case scenario you can reboot the firewall in case it does erase, but Cisco code doesn't just erase. Again, I haven't used ASA Firewalls a whole bunch so...
0
 
LVL 9

Accepted Solution

by:
gavving earned 2000 total points
ID: 35140913
On the ASA (at least 8.2.4 and lower for sure), the interface names are just aliases masking the real interface and do not 'float'.  If you move the interface name to another physical or logical interface, then all of the config still stays pointed to the old interface, and doesn't 'move' to the new interface.

For this reason when I do something like this I create cut-n-paste text file to remove all of the interface specific commands, change the interface name, then paste all of them back in.  First I copy the sections of the configuration that use the interface name.  You can use "show run | grep inside2", but you'll likely have to add some section headers to that output.  For example if you have aaa-servers configured, those usually specify an interface name.  Once I've got all the commands out of the config that specify the interface name copy them in full in the same text file below the existing commands.  Change the first set of commands to have 'no' in front of them.

Basic sequence would be:
- paste in all the 'no' commands to remove the entries that refer to the inside2 interface
- Reconfigure the interfaces with VLANs, configure inside2 on a sub interface that you want with the same IP
- paste back in all the correct commands that refer to inside2.
- test

If you want to provide a sanitized code list I could prepare a cut-n-paste example.
0
 
LVL 1

Author Closing Comment

by:jhakie
ID: 35141640
I confirmed this with an old colleague of mine who is an excellent network engineer. Thanks!
0

Featured Post

Moving data to the cloud? Find out if you’re ready

Before moving to the cloud, it is important to carefully define your db needs, plan for the migration & understand prod. environment. This wp explains how to define what you need from a cloud provider, plan for the migration & what putting a cloud solution into practice entails.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

WARNING:   If you follow the instructions here, you will wipe out your VTP and VLAN configurations.  Make sure you have backed up your switch!!! I recently had some issues with a few low-end Cisco routers (RV325) and I opened a case with Cisco TA…
On Feb. 28, Amazon’s Simple Storage Service (S3) went down after an employee issued the wrong command during a debugging exercise. Among those affected were big names like Netflix, Spotify and Expedia.
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…
Suggested Courses

649 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question