Configuration of the Interface under... Required main line?

ASA5520: I'm trying to implement a subinterface for my 2 apart from the IPs (we have 2 pipes entering the data center). I just added a configuration with 2 secondary Interfaces because I didn't have enough ports with the help of g0/3 of our Interface failover (active / standby config). I was just wondering if I need to set up a trunk as to allow the communication? I have attached all ports on a switch and tried ping the secondary Interfaces of a server on the same subnet, but I can't ping interfaces. I have not implemented a main line and I was wondering if this would be the reason? I use a Dell 2724 switch so maybe that's the reason why it won't work? I could * really * use to help with this problem because I am at a loss... I added my current config to post so I hope this helps to clarify my situation and the installation program.

See the ICM-asa01 (config) # executes

: Saved

:

ASA Version 7.0 (4)

!

icm-xxxxx host name

xxxxxxxx.com domain name

!

interface GigabitEthernet0/0

No nameif

security-level 0

no ip address

!

interface GigabitEthernet0/0.1

VLAN 10

nameif Outside1

security-level 0

IP address 66.38.x.x 255.255.x.x Eve 66.38.x.x

!

interface GigabitEthernet0/0.2

VLAN 20

nameif Outside2

security-level 0

IP address 64.187.x.x 255.255.x.x Eve 64.187.x.x

!

interface GigabitEthernet0/1

nameif DMZ

security-level 100

IP address 255.255.x.x 10.10.x.x ensures 10.10.x.x

!

interface GigabitEthernet0/2

nameif private

security-level 40

IP address 255.255.x.x 192.168.x.x ensures 192.168.x.x

!

interface GigabitEthernet0/3

STATE/LAN failover Interface Description

!

interface Management0/0

STATE failover Interface Description

No nameif

security-level 100

IP address 192.168.x.x 255.255.x.x

!

passive FTP mode

clock timezone IS - 5

clock to summer time EDT recurring

pager lines 24

Enable logging

monitor debug logging

asdm of logging of information

MTU 1500 Outside1

MTU 1500 Outside2

MTU 1500 DMZ

MTU 1500 private

failover

primary failover lan unit

local failover FoInt GigabitEthernet0/3 network interface

failover replication http

link failover FoInt GigabitEthernet0/3

failover interface ip FoInt 192.168.x.x 255.255.x.x Eve 192.168.x.x

the interface of the monitor Outside1

the interface of the monitor Outside2

Thank you

Chris

Hi Chris,

When you have created a sub-intf, it will automatically set the physical interface to use the trunk with dot1Q encap. No order of trunk/encap is required compared to spend. The rest must be supported by the switch, for example allowing to what vlan borrow and be associated with the respective subinterface.

For example, if your Outside2 of Outside1 & is associated with the Vlan 10 and Vlan 20 respectively, the trunk of the switch (with dot1Q encap) must allow to these VLANS to pass through. Other than that, the configured IP subnet will determine how the traffic on the side switch vlan reach vlan firewall-side

Rgds,

AK

Tags: Cisco Security

Similar Questions

  • ACS - 4.1 - does not display Radius (Nortel) in the configuration of the Interface

    We have a GBA running on Windows we can see the Radius (Nortel) option in the Configuration of the Interface.

    Anyone deal with this issue?

    It's probably because you don't have any AAA devices configured for RADIUS (Nortel). IF you set one, it will appear in the configuration of the interface

    Nicolas

    ===

    Remember responses of the rate that you find useful

  • ASA 5540 - cannot ping inside the interface

    Hi all. We have recently upgraded PIX to ASA5540 and we saw a strange thing going. In a Word, we can ping the inside interface of the ASA from any beach on our 6500 network (which is connected directly behind the ASA on the inside), but one where our monitoring tools are placed. Inside there is an ACL that allows all of our core networks, but it does not help that the interface is really strange.

    In the ASDM, I see messages like this:

    ID ICMP echo request: 2004 x.x.x.x y.y.y.y on the inside interface to. I don't think that's the problem, but I could be wrong.

    This is also the configuration of the interface VLAN VIRTUAL local area network from which we cannot ping inside the interface we can ping to and since this VLAN and machines without problem. The only problem is ping the inside interface of the ASA.

    interface Vlanx

    IP x.x.x.x 255.255.255.0

    IP broadcast directed to 199

    IP accounting output-packets

    IP pim sparse - dense mode

    route IP cache flow

    load-interval 30

    Has anyone experiences the problem like this before? Thanks in advance for any help.

    Can you post the output of the following on the ASA:-

    display the route

    And the output of your base layer diverter: -.

    show ip route<>

    HTH >

  • WLC - slot configuration of the dynamic Interface DHCP settings

    Hi guys,.

    If I have a dynamic interface that is connected to a subnet where the router interfaces have DHCP servers configured under the orders of support address, do I need to configure the DHCP fields in the dynamic interface configuration?

    I have the support address configured on routers connected AND these fields configured with the same DHCP servers.

    I was wondering if I can take the IP address of the configuration of WLC?

    Thx a lot indeed.

    Ken

    Ken, the DHCP address in the dynamic interface, is the address the WLC is unicast the DHCP request when a client tries to use this interface. In normal operation, this address is needed. Is there a way to get the WLC to fill the package to the wire to make it a show instead of a unicast packet. CLI command is dhcp proxy disable config.

    But I think that even if you issue the CLI command, the software wants the DHCP address in the dynamic interface.

    HTH,

    Steve

  • Cannot configure the store under OpenSUSE 12.1

    Hello. I can't go beyond to configure the store under OpenSUSE 12.1; the same error with java or java 1.6.0_24 1.7.0_5, adminboot_0.log or snaboot_0.log do not display error messages, Oracle NoSQL is listening on port 5000 and 5001, port 1099 does not appear under netstat, / etc/hosts has 127.0.0.1 localhost, the firewall is enabled or not, it's a Virgin OpenSUSE installation under VirtualBox, logged as root in the shell , or logged in as root on the desktop. The same Installation of NoSQL Oracle scripts work under Solaris, Debian, CentOS, Fedora. The following address (80.156.86.78) is that a default address of the Deutsche Telekom redirects routers for unknown IP addresses. Any ideas where I should look? Maybe some programs installed by default in OpenSUSE interferes with Oracle NoSQL? Thank you, Jesus.

    java-jar ${KVHOME}/lib/kvstore-${VERSION}.jar runadmin-port 5000 - host localhost

    Exception in thread "main" java.rmi.ConnectException: connection refused to host: 80.156.86.78; nested exception is:
    java.net.ConnectException: connection timed out
    at sun.rmi.transport.tcp.TCPEndpoint.newSocket(TCPEndpoint.java:619)
    at sun.rmi.transport.tcp.TCPChannel.createConnection(TCPChannel.java:216)
    at sun.rmi.transport.tcp.TCPChannel.newConnection(TCPChannel.java:202)
    at sun.rmi.server.UnicastRef.invoke(UnicastRef.java:128)
    at java.rmi.server.RemoteObjectInvocationHandler.invokeRemoteMethod(RemoteObjectInvocationHandler.java:194)
    at java.rmi.server.RemoteObjectInvocationHandler.invoke(RemoteObjectInvocationHandler.java:148)
    to $Proxy0.getSerialVersion (Unknown Source)
    to oracle.kv.impl.util.registry.RemoteAPI. < init > (RemoteAPI.java:32)
    to oracle.kv.impl.admin.CommandServiceAPI. < init > (CommandServiceAPI.java:48)
    at oracle.kv.impl.admin.CommandServiceAPI.wrap(CommandServiceAPI.java:55)
    at oracle.kv.impl.util.registry.RegistryUtils.getAdmin(RegistryUtils.java:197)
    at oracle.kv.impl.admin.client.KVAdmin.connect(KVAdmin.java:883)
    at oracle.kv.impl.admin.client.KVAdmin.main(KVAdmin.java:2131)
    to oracle.kv.impl.util.KVStoreMain$ 6.run(KVStoreMain.java:188)
    at oracle.kv.impl.util.KVStoreMain.main(KVStoreMain.java:319)
    Caused by: java.net.ConnectException: connection timed out
    at java.net.PlainSocketImpl.socketConnect (Native Method)
    at java.net.AbstractPlainSocketImpl.doConnect(AbstractPlainSocketImpl.java:339)
    at java.net.AbstractPlainSocketImpl.connectToAddress(AbstractPlainSocketImpl.java:200)
    at java.net.AbstractPlainSocketImpl.connect(AbstractPlainSocketImpl.java:182)
    at java.net.SocksSocketImpl.connect(SocksSocketImpl.java:391)
    at java.net.Socket.connect(Socket.java:579)
    at java.net.Socket.connect(Socket.java:528)
    at java.net.Socket. < init > (Socket.java:425)
    at java.net.Socket. < init > (Socket.java:208)
    at sun.rmi.transport.proxy.RMIDirectSocketFactory.createSocket(RMIDirectSocketFactory.java:40)
    at sun.rmi.transport.proxy.RMIMasterSocketFactory.createSocket(RMIMasterSocketFactory.java:146)
    at sun.rmi.transport.tcp.TCPEndpoint.newSocket(TCPEndpoint.java:613)
    ... 14 more

    I tried opensuse under virtualbox. I don't see the same problem you described.

    May I suggest make you an entry in/etc/hosts, which corresponds to the output of the hostname command and use this name instead of 'localhost' for the configuration of KVStore?

  • Images of the application under Oracle XE - how to configure a path alias?

    Hello

    I installed an APEX on XE application that has been developed under Oracle10g and Apache (mainly so I can get a portable demo system).

    There are two application images that display the logo. Under Apache, they were put in a directory and an alias in the httpd.conf file - as described on ProApEx p419.

    My question is: how will I achieve under XE?

    Ideally, I would like my request to the XE and so wanted to create the same alias - but, XE uses Apache and I can't find how to get my recognized images. All images of the Apex are the loading apxldimg script to takes care of that. I have to create a script to load custom for my images so that they come from the database under XE?

    Thanks for your suggestions,
    Steve

    Hello
    You must configure access to the XDB repository via a Protocol (WebDav or FTP), thereafter, you will be able to put the files in a special issue "file system" from the XE.

    You can find some information about it in a post I wrote some time ago, where there are also links to the documentation:

    http://oraclequirks.blogspot.com/2007/12/on-Oracle-XDB-repository-FTP-WebDAV-and.html

    I normally develop on virtual machines XE (running on a Mac), and then deploy a standard 10 G database running on Solaris without problem, it's just a matter to set up the right protocols and keep synchronized directories.

    Bye,.
    Flavio

    ----------------------------------------
    http://www.oraclequirks.com

  • There is a rectangular main srceen of MF transparency, avoiding to me to click on the link under the header that rectangular... Help, please

    There is a transparent rectangle on header main MF srceen, which avoided me click on the link under the rectangular... Help, please
    even when I rebooted the computer, it didn't disappear!
    http://i.imgur.com/WIvyr.PNG

    Start Firefox in Firefox to solve the issues in Safe Mode to check if one of the extensions or if hardware acceleration is the cause of the problem (switch to the DEFAULT theme: Firefox (Tools) > Add-ons > appearance/themes).

  • Cannot acquire image with NI1744 using the interface configuration of Vision Builder AI 2011: error-1073774588

    I use a 1744 OR with NI Vision Builder AI 2011. When I'm in the interface of the inspection, the camera will acquire and display an image. When I go to the configuration interface and try to put in place the stage of image acquisition, I have error-1073774588: the undefined error. I sometimes also 1074396159 error: not enough memory.

    Thank you for your repply Burrito.

    The problem was sloved and two errors went away after I formatted the camera and reinstalled the software on the camera.

  • OfficeJet 7500 has the configuration of the fax machine with 2 telephone lines

    I have an Officejet 7500 a. The phone is a double line, phone double issue. The 2nd line/number is the number of fax. There is also a DSL service on the line and an answering machine for two lines on a phone. There is no separate cycles for two numbers.

    For installation, I shared the line out of the wall socket. We're going to the DSL modem. The other goes to a DSL filter.

    I tried to hang the black line of HP filter, then the line-1 printer. Then, out of the printer 2 - ext to a separator with several phones, including one with an answering machine. However, all the features of line 2 has been removed from all phones. I guess the line black/printer fails to pass. However I could pass the test of fax,

    So I had the idea of dividing the two lines into individual lines, feed on the second line in the printer (using the HP black line) and then again, and then recombine the lines and send them on phones. Now all the features of two line seems to work for phones, but when I run the fax test, it does not say "you do not use the type of appropriate phone cord.

    It looks like this:

    DSL filter - Splitter-L1 - L1-Splitter (recombine) - phones

    -L2 - HP Black line - 1-line 2 - ext - L2-

    I don't know why it's a failure, or what I have to do to make this work?

    For completeness, the separator is a 3 line separator, but we have nothing on the line 3. It is divided as follows:

    L1 + L2 + L3 Splitter - L1 + L3 (effectively L1)-cross

    -L2 + L3 (effectively L2)-for Officejet

    -L1 + L2 + L3 (not used)

    Ideas?

    Well, I seem to be at the end of the game. I tried sons of single line of the fax to the telephone/answering machine and fax test still does not work. I turned off also error correction mode and that made no difference.

    BUT it doesn't matter because the phones and fax all seem to work very well. I sent a fax to the service HPFAXME (several times) and it worked fine and in. The answering correctly and fax catch fax calls and ignores the voice calls. If someone meets the fax call they hear 3 beeps and the line is silent. In case, answering machine or direct pick-up on any phone, the fax is correctly. I also tried the FaxZero service and it worked fine.

    So, I will be content with that, even though the fax test fails. It bothers me because I do not let "loose ends" lying around, but since I can't read the mind of the engineers who designed it, and how they expected over this configuration, which I think would be relatively common, I'm just spinning my wheels.

  • When you try to add a network route with the "route add" command in the command line, I get the message "the requested operation requires a rise."

    Elevation required to route add command

    When you try to add a network route with the "route add" command in the command line, I get the message "the requested operation requires a rise."  What is the correct syntax to use?

    You can watch using the PowerShell...

    http://TechNet.Microsoft.com/en-us/library/bb978526.aspx

    http://TechNet.Microsoft.com/en-us/scriptcenter/dd742419.aspx

    .. .and post questions about Windows PowerShell forum...

    http://social.technet.Microsoft.com/forums/en/winserverpowershell/threads

  • ASA 5510 Configuration. How to set up 2 outside the interface.

    Hello

    I have Cisco ASA 5510 and the desktop, I want to create a new route to another (external) router to my ISP.

    The workstation I can Ping ASA E0/2 interface but I cannot ping the router ISP B inside and outside of the interface.

    I based my setup on the existing configuration. which so far is working

    interface Ethernet0/0
    Outside of the interface description
    nameif outside
    security-level 0
    IP 122.55.71.138 address 255.255.255.2
    !
    interface Ethernet0/1
    Inside the interface description
    nameif inside
    security-level 100
    IP 10.34.63.252 255.255.240.0
    !
    interface Ethernet0/2
    Outside of the interface description
    nameif outside
    security-level 0
    IP 121.97.64.178 255.255.255.240
    !

    Global 1 interface (outside)

    global (outside) 2 interface (I created this for E0/2)
    NAT (inside) 0 access-list sheep

    NAT (inside) 1 10.34.48.11 255.255.255.255 (work: router ISP inside and outside interface E0/0)

    NAT (inside) 2 10.34.48.32 255.255.255.255 (work: E0/2 router ISP on the inside interface only but cant outside ping).

    Route outside 0.0.0.0 0.0.0.0 122.55.71.139 1 (work)

    Route outside 10.34.48.32 255.255.255.255 121.97.64.179 1 (the new Road Test)

    Router ISP, that a job can ping and I can access the internet

    interface FastEthernet0/0
    Description Connection to ASA5510
    IP 122.55.71.139 255.255.255.248
    no ip redirection
    no ip proxy-arp
    IP nat inside
    automatic duplex
    automatic speed
    !
    the interface S0/0
    IP 111.54.29.122 255.255.255.252
    no ip redirection
    no ip proxy-arp
    NAT outside IP
    !
    IP nat inside source static 122.55.71.139 111.54.29.122
    IP http server
    IP classless
    IP route 0.0.0.0 0.0.0.0 Serial0/0

    FAI 2

    interface FastEthernet0/0 (SAA can ping this interface)
    Description Connection to ASA5510
    IP 121.97.64.179 255.255.255.248
    no ip redirection
    no ip proxy-arp
    IP nat inside
    automatic duplex
    automatic speed
    !
    interface E0/0 (ASA Can not ping this interface)
    IP 121.97.69.122 255.255.255.252
    no ip redirection
    no ip proxy-arp
    NAT outside IP
    !
    IP nat inside source static 121.97.64.179 121.97.69.122
    IP http server
    IP classless
    IP route 0.0.0.0 0.0.0.0 E0/0

    CABLES

    ASA to router ISP B (straight cable)

    Router ISP in the UDI (straight cable)

    Hope you could give some advice and the solution for this kind of problem please

    Hello

    Are you able to ping the router IP of the interface of the device of the ASA? If so, try a trace of package on the device of the SAA for traffic to the IP address of the router.

    Thank you and best regards,

    Maryse Amrodia

  • SG300-20 - configure DHCP on the interface VLAN

    I have read the different partners of the discussions on the SG300 and SG500 going on regarding the high setting of VLAN and DHCP on VIRTUAL networks.  For some reason, I could not get even this simple task to work.

    First thing I did was update my version firmware and boot as follows:

    SW version 1.3.7.18 (date of 12 January 2014 time 18:02:59)

    Start the 1.3.5.06 version (dated 21 July 2013 times 15:12:10)

    HW version V02

    When I rebooted the SG300 after the SW/Boot updates the boot configuration has been crushed and I had to configure my switch from scratch.  The intention is to have two VIRTUAL networks:

    VLAN 1: all the devices, servers, etc.

    VLAN 2: subnet basis which distributes DHCP addresses

    The SG300-20 is connected to a router Asus RT-AC66U on the 192.168.1.x subnet and provides access to the internal network and WiFi access (IP address of the router is 192.168.1.1 and the default gateway).  Everything works without any problem.  So my task is simply to create 2 VLANS on 192.168.2.x subnet and use DHCP to assign addresses.  I spent many hours on it and I still can't get it to work.  When I connect a laptop to the port (GI8) assigned to 2 VLANS, I end up finding a few wobbly 169.254.x.x address.  I definitely thought something would not 'easy' that hard to set up, but apparently I was wrong.

    The SG300 is running in mode L3 as shown in my running-config below.

    Someone gets to see something which could prevent my client from the laptop to receive the interface VLAN 2 DHCP IP addresses that are not on the 192.168.2.x subnet?

    Any ideas / suggestions would be greatly appreciated!

    Here's my running-config:

    config-file-header
    MYSTICSW1
    v1.3.7.18 / R750_NIK_1_35_647_358
    CLI v1.0
    router adjustment system mode

    SSD of encrypted file indicator
    @
    SSD-control-start
    config of SSD
    control of password file unrestricted SSD
    no control of the integrity of the file ssd
    SSD-control-end cb0a3fdb1f3a1af4e4430033719968c0
    !
    database of VLAN
    VLAN 2
    output
    Add a voice vlan Yes-table 0001e3 Siemens_AG_phone___
    Add a voice vlan Yes-table 00036 b Cisco_phone___
    Add a voice vlan Yes-table 00096e Avaya___
    Add a voice vlan Yes-table 000fe2 H3C_Aolynk___
    Add a voice vlan Yes-table 0060 b 9 Philips_and_NEC_AG_phone
    Add a voice vlan Yes-table 00d01e Pingtel_phone___
    VLAN voice Yes-table add Polycom/Veritel_phone___ 00e075
    Add a voice vlan Yes-table 00e0bb 3Com_phone___
    Hello interface range vlan 1
    hostname MYSTICSW1
    host 192.168.1.15 record
    logging source hostname id
    username privilege 15 b4a0fcf20b2cd9d80a55b06ab8f83277f9733904 encrypted password cisco
    location of the SNMP-Server Office
    clock timezone ""-5
    DST Web recurring U.S. clock.
    clock source sntp
    unicast SNTP client enable
    unicast SNTP client survey
    survey of 192.168.1.10 SNTP server
    !
    interface vlan 1
    IP 192.168.1.254 255.255.255.0
    no ip address dhcp
    !
    interface vlan 2
    name MysticWAN
    192.168.2.254 IP address 255.255.255.0
    !
    interface gigabitethernet8
    switchport mode access
    switchport access vlan 2
    !
    output
    Default IP gateway 192.168.1.1

    Thanks in advance!

    Clint Lambert

    Clint, please see this post

    https://supportforums.Cisco.com/message/4178990#4178990

    -Tom
    Please mark replied messages useful
    http://blogs.Cisco.com/smallbusiness/

  • Configuration of the PIX firewall Interface

    Hello

    On a PIX 525 running ver 6.3 4 port 10/100 card installed it will be possible to configure interfaces as follows:

    E0 - inside interface

    E1 - failover stateful Firewall

    E2 - Firewall failover monitoring link

    E5 - outside interface

    I'm basically is unsure as to if it is possible to move the external interface to its default configuration as e0 to E5, and even if it will be possible to specify e0 as the interface instead of the default E1 confiuration inside = inside.

    Another quickie - I guess that with the additional 4 port 10/100 card installed my interfaces will be numbered e0 - e5. Is this correct?

    Thank you.

    Said Cisco documentation is not possible to change the name and the security level of inside interface, but I experience it is possible:

    nameif ethernet1 failover security50

    nameif ethernet5 off security0

    etc...

    I would not recommend doing in a production environment because it would create a lot of confusion...

    525 has two fixed interfaces e0 e1 - card expansion port 4 should therefore be numbered e2, e3 (from left to right)

    M.

    Hope that helps the rate if it isn't

  • Get speech recognition error message could not start because the configuration of the language is not supported, the language must match the language of the user interface

    I am running Windows 7 Ultimate 32 bit, when I run speech recognition it fails and the following message appears,

    Voice recognition couldn't start because the configuration of the language is not supported, the language must match the language of the user interface.

    I tried to change the language, then back to British English, but the problem is still there, I'd appreciate any help with this problem

    Is there a solution to this problem yet?

  • Update a UDA at a member of the main lines of the Calc script?

    Happy new year everyone!

    Is it possible to update a UDA at a member of the main lines of the Calc script? There is a custom for that function?

    We want to check the data, and then update UDA based on what is our data.

    Thank you.

    Not that I know, and it is not possible to write one, since you probably can't restructure with the running calculation (chickens and eggs).

    More likely, you will need to do a multi-step process; export the members that you want to set up a file via DATAEXPORT conditions or report designer, and then use this output to feed in an accumulation of dimension with an appropriate load rule.

    Or write a Java API to fully customized program.

    I'm also curious about the driving condition, as it is a rather unusual request.

Maybe you are looking for