I am attempting to migrate from 515's to 5520's. Due to the ASA having fewer eth interfaces than the PIX, I am trying to bring two DMZ's (both on 2950 switches)in to a switch (also a 2950, which I'll call the "bridge") on separate VLAN's, then bring them into the ASA through subinterfaces.
The problem I have is that the bridge 2950 can see the DMZ 2950's, and can see the physical interfaces on the ASA, but the real traffic is not passing from the bridge 2950 to the ASA.
If I understand correctly, the 2950 cannot do multiple VLAN's with assigned addresses, but it should be able to handle them as currently configured, which is with an address assigned only to vlan1.
I have the switchports set up as trunks, with the appropriate VLAN's assigned. I don't see an available command on the ASA's interface for encapsulation, and based on research, I'm assuming it defaults to dot1q.
So right now I'm not sure if this is a VLAN configuration issue, hardware limitation issue, encapsulation issue or something else entirely.
I've been looking at this a while, and may be missing something simple. Any help would be appreciated.