[c-nsp] Transparent ASA and Dot1q

jcovini at free.fr jcovini at free.fr
Thu Feb 14 09:06:48 EST 2008


Do you know if ASA set to transparent firewall mode is supporting dot1q tagged
frames ?

I am planning as follows but wanna make sure that will work :

My outside interface will connect to a dot1q interfaces of a "classic" L3
firewall, encapsulating 2 VLANs.
My inside interface will connect to a L2 switch port set also in dot1q and
encapsulating the same 2 VLANs.
I found no way to create/trunk VLANs in transparent mode (rev 7.0.7).

Will the ASA accept and filter the traffic, or will the "L2 decode drops"
counters will increase indefinitely ;-) ?

jc


More information about the cisco-nsp mailing list