Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

ASA VLAN subinterfaces

When I configure subinterfaces on an ASA, how does the security level of the physical interface interact with the security levels of the subinterfaces? Can I make the subinterfaces security levels different from the security level of the physical interface and how is this handled?

TIA

  • Other Security Subjects
1 REPLY

Re: ASA VLAN subinterfaces

If you use subinterfaces, you typically do not also want the physical interface to pass traffic, because the physical interface passes untagged packets. Because the physical interface must be enabled for the subinterface to pass traffic, ensure that the physical interface does not pass traffic by leaving out the nameif command. If you want to let the physical interface pass untagged packets, you can configure the nameif command as usual.

The configuration of security levels on sub-interface is the same as physical interfaces. Here's a document on security levels.

http://cisco.com/en/US/docs/security/asa/asa70/configuration/guide/intparam.html

HTH

134
Views
0
Helpful
1
Replies