ASA questions

Unanswered Question
Jan 15th, 2008
User Badges:


I have a setup with 1 ASA5520 with 4 interfaces. I need to connect 2 core switches (Cat65xx) to two of the interfaces, while another 2 interfaces goes to the internet router and the dmz respectively. The core switches are running in a redundant topology setup, and the 2 links to the firewall are supposed to be running simultaneously (ASA running in routed mode, the 2 internal links are routed links).

My question is:

Can i use 1 of the network port on the ASA and set it up as a trunked link with 2-3 vlans? All the hosts in those vlans will be forced to use the ASA as its default gateway.



  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
srue Tue, 01/15/2008 - 20:57
User Badges:
  • Blue, 1500 points or more

you can create subinterfaces on the ASA as follows:

int eth0/2

no shut

int eth0/2.100

vlan 100

int eth0/2.200

vlan 200

int eth0/2.300

vlan 300


that's just an example. the subinterface number does not have to be the same as the vlan, but it helps making the config more readable.

It will then use dot1q on this connection for VLAN tagging. the physical interface (in this case, eth0/2) passes untagged traffic, only if you apply the nameif command.

..for more details


This Discussion