SSM Module Gig interface in ASA 5520

Unanswered Question
Jan 5th, 2009

Hi All,

I have ASA 5520 installed in network. This ASA is having SSM module with 4 gig ports.

Can these ports on SSM module be utilized as normal interfaces of firwall? Is if , a saparate zone, for example DMZ1, can be introduce on the gig ports of SSM module?

Pls advice!


I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
sachinraja Mon, 01/05/2009 - 12:33

hello Patni

Yeah.. you can.. these are extension modules, which can be used to increase the number of DMZ interfaces.. by default the inbuilt Gig interfaces are taken as inside, and outside segments..

To connect to different server segments, you can use the 4 port GE module, and configure DMZ's on those. In case you need more than 4 DMZ's, ASA also supports VLAN trunking, which means on a single GE port, you can configure multiple DMZ's.. :)

Hope this helps.. all the best.. rate replies if found useful..


patnisez1 Mon, 01/05/2009 - 23:53

Hi Raj,

Firstly thanks for replying!

Hope you have understood my worry point, which is deploying/configuring Gig interfaces on SSM module itself. ( other than the default interface availiable on ASA 5520).


sachinraja Tue, 01/06/2009 - 06:28


Ya.. you can.. 4 GE module will just extend your subnets or DMZ.. you can , for sure deploy and configure Gig interfaces on SSM, according to your network design. No need to worry.

Hope this helps.. all the best..



This Discussion