Avatar of jbell72
jbell72
 asked on

ASA

I have an ASA with 3 vlans. The 3rd vlan has a status of down even though I have given it the no shutdown command on the vlan interface? Any ideas?
Cisco

Avatar of undefined
Last Comment
Benjamin Van Ditmars

8/22/2022 - Mon
Ernie Beek

No interfaces assigned to the vlan?
jbell72

ASKER
I havent assigned any interfaces yet to the vlan.....
ASKER CERTIFIED SOLUTION
Svet Paperov

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
SOLUTION
Ernie Beek

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
jbell72

ASKER
I was able to add a  third vlan, it just says status down when I do a "show switch vlan". I will log in now and try to assign an interface to the vlan.


All of life is about relationships, and EE has made a viirtual community a real community. It lifts everyone's boat
William Peck
jbell72

ASKER
I just want the 3rd vlan to be this small network for the 2 exchange servers 2nd nic. They will only talk to each other on this vlan....would that work on this ASA?
SOLUTION
Svet Paperov

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
jbell72

ASKER
So I can have the 3rd vlan but I have to have a no forward staatement to the inside vlan???
Svet Paperov

Correct. With the basic licence of 5505 we cannot access the DMZ (third VLAN) from Inside. To lift that restriction you need security plus licence.
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
jbell72

ASKER
Hmm, I added an onterface to this vlan. It now says staus up, but when I ping the ip of the vlan interface all I get back is ????? from the ping. And this is from inside the asa.
jbell72

ASKER
How do I determine if  I have a basic license or not?
jbell72

ASKER
oh nevermind...show activation-key detail

I started with Experts Exchange in 2004 and it's been a mainstay of my professional computing life since. It helped me launch a career as a programmer / Oracle data analyst
William Peck
Svet Paperov

Run sh ver command in CLI or in License tab of Device information in ASDM
jbell72

ASKER
OK, 1 more time so I am clear.
!
interface Vlan1
 nameif inside
 security-level 100
 ip address 192.168.50.1 255.255.255.0
!
interface Vlan2
 nameif outside
 security-level 0
 ip address 10.1.10.11 255.255.255.0
!
interface Vlan3
 no forward interface Vlan1
 no nameif
 security-level 100
 ip address 192.168.60.1 255.255.255.0


So from inisde my asa I ping 192.168.60.1 (VLAN 3 IP) and I get back

 ping 192.168.60.1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.60.1, timeout is 2 seconds:
?????
Success rate is 0 percent (0/5)


So that is usposed to happen? I cannot ping internally from asa to vlan3?
Svet Paperov

Correct. That's the limitation of Base license - you can access outside from the DMZ (your VLAN 3) but you cannot access inside interface. To lift that limitation you need security plus licence
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
jbell72

ASKER
Where can I buy and download the security plus license?
Svet Paperov

Any Cisco dealer, depending on your location. The licence is just an activation key that you will have to enter on the firewall.
Benjamin Van Ditmars

With the asa5505 with a basic os you can make a thrid vlan, that has access to the LAN or WAN interface. but not both. this is the ristricted DMZ but if you need 2 exchange servers to talk to the other why not create a vlan on a swicht ?. this is much cheaper
Experts Exchange is like having an extremely knowledgeable team sitting and waiting for your call. Couldn't do my job half as well as I do without it!
James Murphy