Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Multiple VLANs behind single firewall segment?

Here is what I need to do.  I need to create a firewalled segment that not only separates hosts from general population, but also from each other.  The solitary confinement of firewalled segments.

I know that I could create a bunch of sub-interfaces, one for each host or group that needs to be isolated, but I'd really rather not have to do that if possible.  1) It could become a management nightmare between ACLs and sub-interfaces and 2) it's a waste of IP addresses.

Is there any way that I can create a bunch of separate VLANs behind the firewall and have them all terminate at the firewall, using a single firewall IP address for the gateway?

Kind of like this?

VLAN 1 - hosts and

VLAN 2 - hosts

Firewall DMZ Interface -
VLAN 3 - hosts and

This way, the hosts are isolated and can't talk to each other unless they're on the same VLAN.

So, 1) does this make sense? and 2) is it possible?

I'm working with an ASA 5510 running 8.2.4(4).




Multiple VLANs behind single firewall segment?

HI there,

Please read this thread at below link, it was very much similar implementation was done.


Rizwan Rafeek