We're Sorry, Full Content Access is for Members Only...

If you like to keep on reading, Become a Member Now! Here is Why:

  • Learn any CCNA, CCNP and CCIE R&S Topic. Explained As Simple As Possible.
  • Try for Just $1. The Best Dollar You've Ever Spent on Your Cisco Career!
  • Full Access to our 537 Lessons. More Lessons Added Every Week!
  • Content created by Rene Molenaar (CCIE #41726)


323 New Members signed up the last 30 days!


100% Satisfaction Guaranteed!
You may cancel your monthly membership at any time.
No Questions Asked!


Notable Replies

  1. hi renee ;
    I was trying to work on your toplogy above but for some reason I cant ping to otherside of ASA .interfaces are up and even applied this default command

    ASA1(config)# policy-map global_policy
    ASA1(config-pmap)# class inspection_default
    ASA1(config-pmap-c)# inspect icmp

    still doesnt work on my gns3 .do you have any idea about it ?

  2. Rene,


    Working on this Lab using ASA 5505 verison Cisco Adaptive Security Appliance Software Version 8.4(2)

    I tried to replicate the lab above, but I can't add an IP address to the actual interface I need to add them to a VLAN interface. How can I do that and have each zone on a different subnet ?Any advice/example would be greatly appreciated.


    Juan Iniguez

  3. Hi Juan,

    The main difference between the 5505 and the 5510 or higher is that the 5505 has switchports and VLAN interfaces. The 5510 only has L3 interfaces.

    Configuration is similar to a L3 switch, here's an example for an INSIDE and OUTSIDE:

    ASA(config)# interface vlan 100
     ASA(config-if)# nameif OUTSIDE
     ASA(config-if)# security-level 0
     ASA(config-if)# ip address
     ASA(config-if)# no shutdown
     ASA(config-if)# interface vlan 200
     ASA(config-if)# nameif INSIDE
     ASA(config-if)# security-level 100
     ASA(config-if)# ip address
     ASA(config-if)# no shutdown
     ASA(config)# interface ethernet 0/0
     ASA(config-if)# switchport access vlan 100
     ASA(config-if)# no shutdown
     ASA(config-if)# interface ethernet 0/1
     ASA(config-if)# switchport access vlan 200
     ASA(config-if)# no shutdown

    The 5505 is the last ASA that uses these switchports and VLAN interfaces, the 5506 has 8x L3 interfaces.

    Hope this helps!


  4. Hi Juan,

    The only thing you have to do is to make sure that devices on the inside use your ASA as the default gateway. Traffic on the outside should use your ASA as the destination when they want to reach the subnet of your inside or dmz, that's it.

    In this lesson:


    I am using a router on the inside and outside, both are using the ASA as their default gateway.


  5. Hey Rene,

    Is there another protocol/command to allow http traffic through an Cisco ASA other than a ACL?

Continue the discussion forum.networklessons.com

23 more replies