Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

ASA firewall subinterfaces


I'm not very familiar with firewalls, but I've inherited a network with an active/standby 5540 configuration. It looks like the 0/3 interface on the standby firewall is bad, so I recently tried to move the subinterfaces on that interface to the 0/2 interface. (They each only have 3 subifs, and there shouldn't be bandwidth concerns, as there's a bottleneck upstream.) When I did this in a management window (performing the change on the active firewall, and allowing it to replicate to the standby), I changed the subinterface numbers to match their associated VLAN numbers, for both the existing and the migrated subifs on the 0/2 interface. I was able to ping servers on all VLANs from the firewall, but a colleague trying to get in from outside was unable to access them.

Other than the subinterface numbering, and the physical interface on which they reside, nothing in the firewall configuration changed. I don't understand why this would work one way, and not the other.

Any advice I get would be appreciated. I'll do my best to answer any questions.


Re: ASA firewall subinterfaces

You might have got more answers if you'd posted this to Security - Firewalling forum.

If the interfaces are operational, then I'd suspect a NAT issue - perhaps some lines were lost when you renamed the interfaces?

New Member

Re: ASA firewall subinterfaces

Thanks, Grant. This was my first post, and I wasn't sure where to post. I'll repost there.

CreatePlease login to create content