Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
New Member

Any best practices for secondary interface/IP



I am working for translate firewall from to ASA now.  As I know ASA did not support secondary interface IP. 


However, my existing firewall setup is using this method to bind different subnet into single Interface. 


Did any best practices to migrate into ASA environment?



Super Bronze

Hi, This depends on your



This depends on your current environment which we dont know about.


As ASA firewalls can not have secondary IP addresses on a single interface then the typical options would be to either


  • Move the gateway of these internal subnets (which need to be under the same interface) to an internal L3 switch or Router. Then configure a link network between that device and the ASA interface and route the subnets through that link subnet.
  • Configure the subnets to different ASA interface (actual physical interfaces or subinterface if using Trunking) and separate those subnets to different Vlans on your switch network (or if not using Vlans then simply to different switches)


I guess it would also be possible to have 2 separate physical ASA interfaces connected to the same network switch network (Vlan) where the 2 subnet are used and just configure the other gateway on the other interface and the other subnet on the other physical interface. I would assume it could work but I am really hesitant to even write this as this would certainly be something that I would not even consider unless in some really urgent situation where there was no other options (for some reason).


- Jouni

New Member

Hi,Thanks for comment.   It


Thanks for comment.   It looks very hard for me as too many subnets together, so using different ASA interface must not enough to allocate.


I just have dummy L2 switch, so it also hardly to re-locate the gateway at switch level.


I read some material about workaround using ARP proxy.  Like following


Is it possible?



CreatePlease to create content