Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
Community Member

ASA LAN connection


I have just been asked to install a ASA 5510 into our network. I have never used an ASA device so i am looking for the best way to connect it into the network. It will be connected to a 3560 switch. which is part of a vtp domain with 15 vlans. Can i add the ASA over a trunk? I have read that i need security plus license to do this. If this is the case do i need to configure a route on the switch? Any ideas will help.


Hall of Fame Super Blue

Re: ASA LAN connection


Is your 3560 switch doing the inter-vlan routing at the moment ?.

If it is do you have a requirement to firewall traffic between these vlans or is the ASA to protect the vlans from the outside.

If it is to protect from the outside the simplest thing to do is have separate vlan for connectivity between the switch and the router and add a route on the ASA for the internal networks pointing to the vlan interface on the 3560 and then on the 3560 add a default route poiinting to the ASA.

if this isn't what you want could you please elaborate on your requirements.



Community Member

Re: ASA LAN connection

Thanks for the reply.

The 3560 is doing the inter-vlan routing.

The asa is to protect from the outside and maybe provide vpn access. It will be used as a back up route to the internet incase our group internet connection goes down (our group network is managed by an external company).

This solution is what i was thinking of. Thanks for the advice.


CreatePlease to create content