cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
283
Views
0
Helpful
1
Replies

ASA VLAN subinterfaces

f00f1ter
Level 1
Level 1

When I configure subinterfaces on an ASA, how does the security level of the physical interface interact with the security levels of the subinterfaces? Can I make the subinterfaces security levels different from the security level of the physical interface and how is this handled?

TIA

1 Reply 1

Collin Clark
VIP Alumni
VIP Alumni

If you use subinterfaces, you typically do not also want the physical interface to pass traffic, because the physical interface passes untagged packets. Because the physical interface must be enabled for the subinterface to pass traffic, ensure that the physical interface does not pass traffic by leaving out the nameif command. If you want to let the physical interface pass untagged packets, you can configure the nameif command as usual.

The configuration of security levels on sub-interface is the same as physical interfaces. Here's a document on security levels.

http://cisco.com/en/US/docs/security/asa/asa70/configuration/guide/intparam.html

HTH

Review Cisco Networking products for a $25 gift card