Firewall ASA Sub-Inetrface

Unanswered Question
Jan 4th, 2009

i am unable to create sub-inerface on my asa 5540.Failover is active/stand-by.How can i create sunb-interface and vlan in ASA 5540.

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
JORGE RODRIGUEZ Sun, 01/04/2009 - 09:30


Follow this link for configuring subiterfaces, keep in mind, to create subinterfaces you will be using do1q encap so ensure your switch physical connection to ASA port where subinterfaces will be created also be configured for dot1q trunking as well as respective VLANs IDs.

VLANS are created in your L2 switch and pass them to asa via dot1q trunk.

Also you said you have failover pair, I assume you have already configured active/standby and that you have active unit in one switch and standby unit in another switch both switches trunked ,or same switch? so if you are going to create sub-interface in ASA you will have to create dot1q trunk on the switch or swithes for both physical connections of Active FW and Standby FW.

Subinterfaces and dot1q

Look at the topology digram in this scenario Active/Standby to sort of give you a picture of physical connectivity.




This Discussion