• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 611
  • Last Modified:

VLAN's on Catalyst 2960 behind ASA 5505 w/ Security license

Is it possible to create multiple VLAN's on a Catalyst switch behind an ASA 5505? I do have the security license on the ASA.

I am used to being able to do it on a router by creating the sub-interfaces, but cannot do that on the ASA (or can I?)
0
j_crow1
Asked:
j_crow1
1 Solution
 
RafaelCommented:
yes you can create clans on a Cat switch. I have a few behind ASAs.

The command is as follows:

switch#conf t
switch#interface vlan X (X = Number of your vlan, i.e 180)
switch#ip address x.x.x.x y.y.y.y (IP and Subnet Mask, this is normally your GW)
switch#no ip redirects
switch#no ip unreachables
switch#no ip proxy-arp
switch#end
switch#wr mem

Don't forget to set up policy on your ASA to see or route the VLAN traffic as needed.
0
 
Hassan BesherCommented:
yeah why not, Security Plus License: 20

http://www.cisco.com/c/en/us/td/docs/security/asa/asa83/asdm63/configuration_guide/config/intrface.html#wp1082576

http://www.cisco.com/c/en/us/td/docs/security/asa/asa83/asdm63/configuration_guide/config/intrface.html#wp1096308

Just make sure the switch port connected to the ASA is in trunk mode and it's to desirable to allow only the vlans you needed to go through using trunk allowed-vlans, and you should be good to go!
0

Featured Post

Choose an Exciting Career in Cybersecurity

Help prevent cyber-threats and provide solutions to safeguard our global digital economy. Earn your MS in Cybersecurity. WGU’s MSCSIA degree program was designed in collaboration with national intelligence organizations and IT industry leaders.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now