[c-nsp] ASA Transparent Mode with VLAN Trunks

Mike Louis MLouis at nwnit.com
Thu Apr 17 08:59:05 EDT 2008


We are making some progress on this however not completed yet. We had to assign multiple contexts to the firewall as expected, then assign a set of vlans on the outside interfaces (50,51) and then another set of vlans on the inside interfaces (100,101). The ASA would not let me assign the same vlan to the inside and outside interfaces. It appears VLAN tags are stripped in bound to the outside interface of the ASA and then reapplied (with a different tag) on the inside interface. Switches on each side are trunked accordingly. I have one side of the topology, ie one asa with multiple context working, still working on the second device.

 If anyone has a working configuration for this setup, can you please post to this forum?


TIA

Mike
________________________________________
From: cisco-nsp-bounces at puck.nether.net [cisco-nsp-bounces at puck.nether.net] On Behalf Of Tim Franklin [tim at pelican.org]
Sent: Thursday, April 17, 2008 4:28 AM
To: cisco-nsp at puck.nether.net
Subject: Re: [c-nsp] ASA Transparent Mode with VLAN Trunks

On Wed, April 16, 2008 5:37 pm, Ge Moua wrote:
> I tried emailing attachments to the 'list' before, and this was rejected.
> I'm always open to sharing by any means necessary.

Err... paste the text of the config?



_______________________________________________
cisco-nsp mailing list  cisco-nsp at puck.nether.net
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Note: This message and any attachments is intended solely for the use of the individual or entity to which it is addressed and may contain information that is non-public, proprietary, legally privileged, confidential, and/or exempt from disclosure.  If you are not the intended recipient, you are hereby notified that any use, dissemination, distribution, or copying of this communication is strictly prohibited.  If you have received this communication in error, please notify the original sender immediately by telephone or return email and destroy or delete this message along with any attachments immediately.



More information about the cisco-nsp mailing list