Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

ASA 55xx - Layer 2 vs Layer 3 Best Practice?

Depending on the person at TAC some recommend using only layer 2 and while others suggest using layer 3 when using the firewall in routed mode and not utilizing a router. So what does everyone think? Keep in mind the possibility of using VPN access due to hairpin issues.

Should you use a layer 3 switch, define the VLANS, turn on ip routing, and trunk to the firewall interface with VLAN subinterfaces? or

Use a layer 2 switch, define the VLANS, use ip default-gateway, and define static routes on the firewall?

Super Bronze

Re: ASA 55xx - Layer 2 vs Layer 3 Best Practice?

Since you would like to terminate VPN on the ASA, then you would need to go with Layer 3 (routed firewall), because Layer 2 (transparent firewall) does not support VPN termination.

Here are a list of things that are not supported on Layer 2 firewall for your reference:

(Table 4-1     Unsupported Features in Transparent Mode)

The actual doc also explains both firewall as a routed and transparent firewall for your reference:

Hope that helps.

New Member

Re: ASA 55xx - Layer 2 vs Layer 3 Best Practice?

I guess I should have been a little more clear - should the switches be running Layer 2 or Layer 3.

Option 1 - Layer 2 switch, requires trunking and static route statements on the firewall.

Option 2 - Layer 3 switch, use VLAN subinterfaces, trunking.

I think both require static NAT statements to allow the VLANs with same security level to communicate.

Re: ASA 55xx - Layer 2 vs Layer 3 Best Practice?


The fact that you use L2 or L3 switches behind the ASA, it will just change how the ASA look at this devices.

For example,

If you configure the switches at L2, the ASA will look at the switches as regular L2 switches and will share a subnet with the next L3 device on the path to the inside.

If you configure the switches at L3, the ASA will look at those switches as routers.

Which are the benefits or disadvantages of one solution over the other depends on your entire topology (hard to tell without knowing the layout).

If you can post a simple diagram with what you're planning to do, I think you'll get more help here.