Solved

VLAN's on Catalyst 2960 behind ASA 5505 w/ Security license

Posted on 2014-04-21
2
571 Views
Last Modified: 2014-04-24
Is it possible to create multiple VLAN's on a Catalyst switch behind an ASA 5505? I do have the security license on the ASA.

I am used to being able to do it on a router by creating the sub-interfaces, but cannot do that on the ASA (or can I?)
0
Comment
Question by:j_crow1
2 Comments
 
LVL 10

Accepted Solution

by:
Rafael earned 500 total points
Comment Utility
yes you can create clans on a Cat switch. I have a few behind ASAs.

The command is as follows:

switch#conf t
switch#interface vlan X (X = Number of your vlan, i.e 180)
switch#ip address x.x.x.x y.y.y.y (IP and Subnet Mask, this is normally your GW)
switch#no ip redirects
switch#no ip unreachables
switch#no ip proxy-arp
switch#end
switch#wr mem

Don't forget to set up policy on your ASA to see or route the VLAN traffic as needed.
0
 
LVL 6

Expert Comment

by:Hassan Besher
Comment Utility
yeah why not, Security Plus License: 20

http://www.cisco.com/c/en/us/td/docs/security/asa/asa83/asdm63/configuration_guide/config/intrface.html#wp1082576

http://www.cisco.com/c/en/us/td/docs/security/asa/asa83/asdm63/configuration_guide/config/intrface.html#wp1096308

Just make sure the switch port connected to the ASA is in trunk mode and it's to desirable to allow only the vlans you needed to go through using trunk allowed-vlans, and you should be good to go!
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

This is about downgrading PIX Version 8.0(4) & ASDM 6.1(5) to PIX 7.2(4) and ASDM 5.2(4) but with only 64MB RAM and 16MB flash. Background: You have a Cisco Pix 515E which was running on PIX 7.2(4) and its supporting ASDM 5.2(4) without any i…
From Cisco ASA version 8.3, the Network Address Translation (NAT) configuration has been completely redesigned and it may be helpful to have the syntax configuration for both at a glance. You may as well want to read official Cisco published AS…
Illustrator's Shape Builder tool will let you combine shapes visually and interactively. This video shows the Mac version, but the tool works the same way in Windows. To follow along with this video, you can draw your own shapes or download the file…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now