• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 305
  • Last Modified:


Assuming an ASA has an outside interface configured to provide several subinterface with each sub-interface tagged for a unique Vlan eg ( gig 1/1.1 - vlan 100 --- gig 1/1.2 - vlan 200)

Also assuming that that the inside interface has a similar configuration only using different Vlans ( gig 1/2.1 - vlan 110 --- gig 1/2.2 - vlan 210)


How do we ensure that only traffic from Vlan 100 or subinterface Gig 1/1.1 can route to Vlan 110 subinterface gig 1/2.1.  

Also Traffic from Vlan 200 can route to Vlan 210.

It is important that under no circumstances can traffic from Vlan 100 be allowed to route to Vlan 200 or 210.
1 Solution
Henk van AchterbergSr. Technical ConsultantCommented:
interface GigabitEthernet0/0.100
 vlan 100
 nameif vlan100
 security-level 0
 ip address
interface GigabitEthernet0/0.110
 vlan 110
 nameif vlan110
 security-level 0
 ip address
interface GigabitEthernet0/0.200
 vlan 200
 nameif vlan200
 security-level 0
 ip address
interface GigabitEthernet0/0.210
 vlan 200
 nameif vlan210
 security-level 0
 ip address

same-security-traffic permit inter-interface

object network LAN-VLAN100

object network LAN-VLAN110

access-list vlan100_access_in extended permit ip LAN-VLAN100 LAN-VLAN110
access-group vlan100_access_in in interface vlan100

access-list vlan110_access_in extended permit ip LAN-VLAN110 LAN-VLAN100
access-group vlan110_access_in in interface vlan110

object network LAN-VLAN200

object network LAN-VLAN210

access-list vlan200_access_in extended permit ip LAN-VLAN200 LAN-VLAN210
access-group vlan200_access_in in interface vlan200

access-list vlan210_access_in extended permit ip LAN-VLAN210 LAN-VLAN200
access-group vlan210_access_in in interface vlan210
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Get your problem seen by more experts

Be seen. Boost your question’s priority for more expert views and faster solutions

Tackle projects and never again get stuck behind a technical roadblock.
Join Now