cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
860
Views
4
Helpful
3
Replies

PIX/ASA - VLANs in transparent mode?

ssewallatrc
Level 1
Level 1

Is there any problem putting an ASA/PIX in transparent mode on an 802.11Q trunk link? I have an internet router that will do NAT to three VLANS and I want to send that trunk through a transparent ASA-5510 for inspection and then onto the trunk port on an internal router. Any problems with this scenario? Or will I have to let the ASA do the NAT and operate in routed mode?

3 Replies 3

vkapoor5
Level 5
Level 5

The PIX must be configured for 802.1Q encapsulation. In PIX 6.3 a new feature is added, where PIX can create logical interfaces. Each logical interface corresponds to a VLAN in the switch. Refer to Using VLANs with the Firewall for more information.

http://www.cisco.com/en/US/docs/security/pix/pix63/configuration/guide/bafwcfg.html#wp1113411

i'm not sure what you're trying to do, but a firewall is either in transparent mode or routed mode. You can't specify vlans or subinterfaces only.

You can only use two interfaces (plus a mgmt interface) in transparent mode.

see the guidelines here:

http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/fwmode.html#wp1202704

vitripat
Level 7
Level 7

ASA/PIX when in transparent mode works like a bridge. You can use max. 2 interfaces and these two interfaces need to be part of specific VLANs. It looks like you are connecting these inerfaces to trunk ports carrying multiple VLANs, this will not work. I'm not sure whats your network topology, hence cant suggest if routed mode would be a good option for you. Could you please elaborate more on the network design?

Regards,

Vibhor.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: