<?xml version="1.0" encoding="UTF-8"?><rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
> <channel><title>Comments on: Adding a secondary IP address on a Cisco ASA Ethernet interface</title> <atom:link href="http://www.ducea.com/2008/05/31/adding-a-secondary-ip-address-on-a-cisco-asa-ethernet-interface/feed/" rel="self" type="application/rss+xml" /><link>http://www.ducea.com/2008/05/31/adding-a-secondary-ip-address-on-a-cisco-asa-ethernet-interface/</link> <description>The Journal Of A Linux Sysadmin</description> <lastBuildDate>Thu, 09 Feb 2012 03:50:59 +0000</lastBuildDate> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3</generator> <item><title>By: Brett</title><link>http://www.ducea.com/2008/05/31/adding-a-secondary-ip-address-on-a-cisco-asa-ethernet-interface/comment-page-2/#comment-193910</link> <dc:creator>Brett</dc:creator> <pubDate>Tue, 07 Feb 2012 07:11:15 +0000</pubDate> <guid
isPermaLink="false">http://www.ducea.com/?p=241#comment-193910</guid> <description>This solution worked great but we&#039;ve run into an odd issue. Communication between systems on both subnets is perfect with one exception.  Devices on the new subnet cannot communicate with an Exchange Server on the main subnet (no ping reply).  I suspect this has something do with this server having NAT configured on the ASA with an outside IP address...</description> <content:encoded><![CDATA[<p>This solution worked great but we&#8217;ve run into an odd issue. Communication between systems on both subnets is perfect with one exception.  Devices on the new subnet cannot communicate with an Exchange Server on the main subnet (no ping reply).  I suspect this has something do with this server having NAT configured on the ASA with an outside IP address&#8230;</p> ]]></content:encoded> </item> <item><title>By: Mike</title><link>http://www.ducea.com/2008/05/31/adding-a-secondary-ip-address-on-a-cisco-asa-ethernet-interface/comment-page-2/#comment-193657</link> <dc:creator>Mike</dc:creator> <pubDate>Thu, 03 Nov 2011 18:26:57 +0000</pubDate> <guid
isPermaLink="false">http://www.ducea.com/?p=241#comment-193657</guid> <description>I ran into this same issue, but we had already bought the license upgrade.    So I created a second interface called inside2.    But I plugged both interfaces into the same switch without any vlans configured on the switch.   The ASA at the second interface on vlan12 but the switch removed all the tags.    This didn&#039;t work at first until I noticed the sh int inside and sh int inside2 both reported the same MAC address.    I changed the MAC address on inside2.   No it works perfectly.    And works with my vpn tunnels.</description> <content:encoded><![CDATA[<p>I ran into this same issue, but we had already bought the license upgrade.    So I created a second interface called inside2.    But I plugged both interfaces into the same switch without any vlans configured on the switch.   The ASA at the second interface on vlan12 but the switch removed all the tags.    This didn&#8217;t work at first until I noticed the sh int inside and sh int inside2 both reported the same MAC address.    I changed the MAC address on inside2.   No it works perfectly.    And works with my vpn tunnels.</p> ]]></content:encoded> </item> <item><title>By: - Marius -</title><link>http://www.ducea.com/2008/05/31/adding-a-secondary-ip-address-on-a-cisco-asa-ethernet-interface/comment-page-2/#comment-193604</link> <dc:creator>- Marius -</dc:creator> <pubDate>Tue, 11 Oct 2011 01:29:54 +0000</pubDate> <guid
isPermaLink="false">http://www.ducea.com/?p=241#comment-193604</guid> <description>@Patrick: the &quot;Cisco way&quot; is to use VLANs for each network range. (regardless on your license type you are not able to have aliases on the interfaces). Or use another Cisco router to do the intervlan routing (any basic IOS router will have the ability to have interface aliases). hth.</description> <content:encoded><![CDATA[<p>@Patrick: the &#8220;Cisco way&#8221; is to use VLANs for each network range. (regardless on your license type you are not able to have aliases on the interfaces). Or use another Cisco router to do the intervlan routing (any basic IOS router will have the ability to have interface aliases). hth.</p> ]]></content:encoded> </item> <item><title>By: Patrick</title><link>http://www.ducea.com/2008/05/31/adding-a-secondary-ip-address-on-a-cisco-asa-ethernet-interface/comment-page-2/#comment-193603</link> <dc:creator>Patrick</dc:creator> <pubDate>Mon, 10 Oct 2011 05:22:54 +0000</pubDate> <guid
isPermaLink="false">http://www.ducea.com/?p=241#comment-193603</guid> <description>Hi Marius,You say the “Cisco way” to achieve this is to use separate vlans for each network range.
I have the Security Plus license as I had to have an unlimited DMZ.
How can you achieve this the “Cisco way”?
Thank you for your help.</description> <content:encoded><![CDATA[<p>Hi Marius,</p><p>You say the “Cisco way” to achieve this is to use separate vlans for each network range.<br
/> I have the Security Plus license as I had to have an unlimited DMZ.<br
/> How can you achieve this the “Cisco way”?<br
/> Thank you for your help.</p> ]]></content:encoded> </item> <item><title>By: Dratas</title><link>http://www.ducea.com/2008/05/31/adding-a-secondary-ip-address-on-a-cisco-asa-ethernet-interface/comment-page-2/#comment-193591</link> <dc:creator>Dratas</dc:creator> <pubDate>Mon, 03 Oct 2011 12:29:20 +0000</pubDate> <guid
isPermaLink="false">http://www.ducea.com/?p=241#comment-193591</guid> <description>This workaround is not working on ASA 5510 8.0(4)...</description> <content:encoded><![CDATA[<p>This workaround is not working on ASA 5510 8.0(4)&#8230;</p> ]]></content:encoded> </item> <item><title>By: tmg</title><link>http://www.ducea.com/2008/05/31/adding-a-secondary-ip-address-on-a-cisco-asa-ethernet-interface/comment-page-2/#comment-193443</link> <dc:creator>tmg</dc:creator> <pubDate>Thu, 08 Sep 2011 09:03:07 +0000</pubDate> <guid
isPermaLink="false">http://www.ducea.com/?p=241#comment-193443</guid> <description>very useful thanks!</description> <content:encoded><![CDATA[<p>very useful thanks!</p> ]]></content:encoded> </item> <item><title>By: itguy</title><link>http://www.ducea.com/2008/05/31/adding-a-secondary-ip-address-on-a-cisco-asa-ethernet-interface/comment-page-2/#comment-192869</link> <dc:creator>itguy</dc:creator> <pubDate>Wed, 11 May 2011 23:16:03 +0000</pubDate> <guid
isPermaLink="false">http://www.ducea.com/?p=241#comment-192869</guid> <description>Hey Mod,
Where have u been. I have been waiting for your reply for nearly a month.</description> <content:encoded><![CDATA[<p>Hey Mod,<br
/> Where have u been. I have been waiting for your reply for nearly a month.</p> ]]></content:encoded> </item> <item><title>By: scopedial</title><link>http://www.ducea.com/2008/05/31/adding-a-secondary-ip-address-on-a-cisco-asa-ethernet-interface/comment-page-2/#comment-192800</link> <dc:creator>scopedial</dc:creator> <pubDate>Wed, 27 Apr 2011 18:20:57 +0000</pubDate> <guid
isPermaLink="false">http://www.ducea.com/?p=241#comment-192800</guid> <description>awesome!
I had to fiddle with sub-interfaces but it is working now!
(PIX 515 with 8.0(4))The following is from Cisco Support...&quot;In Cisco IOS you can configure router interfaces with one or more secondary IP addresses (&quot;ip address .... secondary&quot;). The PIX however is a security device and will not let you configure multiple IP addresses on an interface. So configuring a PIX interface with a secondary IP address is not possible. An additional IP would need to be configured on a new interface.&quot;</description> <content:encoded><![CDATA[<p>awesome!<br
/> I had to fiddle with sub-interfaces but it is working now!<br
/> (PIX 515 with 8.0(4))</p><p>The following is from Cisco Support&#8230;</p><p>&#8220;In Cisco IOS you can configure router interfaces with one or more secondary IP addresses (&#8220;ip address &#8230;. secondary&#8221;). The PIX however is a security device and will not let you configure multiple IP addresses on an interface. So configuring a PIX interface with a secondary IP address is not possible. An additional IP would need to be configured on a new interface.&#8221;</p> ]]></content:encoded> </item> <item><title>By: carlivar</title><link>http://www.ducea.com/2008/05/31/adding-a-secondary-ip-address-on-a-cisco-asa-ethernet-interface/comment-page-2/#comment-192792</link> <dc:creator>carlivar</dc:creator> <pubDate>Tue, 26 Apr 2011 22:40:45 +0000</pubDate> <guid
isPermaLink="false">http://www.ducea.com/?p=241#comment-192792</guid> <description>I hate the ASA. What a piece of crap. Ironically I discovered this lack of functionality as part of a project to migrate to real firewalls: Juniper SRX.</description> <content:encoded><![CDATA[<p>I hate the ASA. What a piece of crap. Ironically I discovered this lack of functionality as part of a project to migrate to real firewalls: Juniper SRX.</p> ]]></content:encoded> </item> <item><title>By: itguy</title><link>http://www.ducea.com/2008/05/31/adding-a-secondary-ip-address-on-a-cisco-asa-ethernet-interface/comment-page-2/#comment-192708</link> <dc:creator>itguy</dc:creator> <pubDate>Fri, 15 Apr 2011 09:41:28 +0000</pubDate> <guid
isPermaLink="false">http://www.ducea.com/?p=241#comment-192708</guid> <description>Hi thank for the wonderful info. I have a small scenario im trying in my pc.
I have an asa 5505 with inside interface 192.168.1.0/24 and outside 192.168.0.0/24
The inside interface pc&#039;s are assigned dhcp ip addresses from the asa. On one of the inside pc&#039;s i have a vmware workstation in the network 10.10.10.0/24
i have done everything u mentioned here but the vmware workstation does not connect to the internet.
ASA Version 8.2(1)
!
hostname ciscoasa
enable password  encrypted
passwd  encrypted
names
!
interface Vlan1
mac-address xxxx.xxxx.xxxx
nameif inside
security-level 100
ip address 192.168.1.1 255.255.255.0
!
interface Vlan2
nameif outside
security-level 0
ip address 192.168.0.10 255.255.255.0
!
interface Ethernet0/0
switchport access vlan 2
!
interface Ethernet0/1
!
interface Ethernet0/2
speed auto
duplex auto
!
interface Ethernet0/3
!
interface Ethernet0/4
speed auto
duplex auto
!
interface Ethernet0/5
!
interface Ethernet0/6
!
interface Ethernet0/7
!
ftp mode passive
same-security-traffic permit inter-interface
same-security-traffic permit intra-interface
access-list access_inbound extended permit tcp any host 192.168.1.0 eq www
access-list access_inbound extended permit tcp any host 10.10.10.0 eq www
pager lines 24
logging enable
logging timestamp
logging asdm informational
mtu inside 1500
mtu outside 1500
icmp unreachable rate-limit 1 burst-size 1
icmp deny any outside
asdm history enable
arp inside 10.10.10.10 503d.e553.8cdb alias
arp timeout 14400
global (outside) 1 interface
nat (inside) 1 10.10.10.0 255.255.255.0
nat (inside) 1 192.168.1.0 255.255.255.0
nat (inside) 1 0.0.0.0 0.0.0.0
access-group access_inbound in interface outside
route outside 0.0.0.0 0.0.0.0 192.168.0.1 1
route inside 10.10.10.0 255.255.255.0 192.168.1.1 1
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
timeout tcp-proxy-reassembly 0:01:00
dynamic-access-policy-record DfltAccessPolicy
http server enable
http 192.168.1.0 255.255.255.0 inside
no snmp-server location
no snmp-server contact
snmp-server enable traps snmp authentication linkup linkdown coldstart
crypto ipsec security-association lifetime seconds 28800
crypto ipsec security-association lifetime kilobytes 4608000
telnet timeout 5
ssh timeout 5
console timeout 0
management-access inside
dhcpd auto_config outside
!
dhcpd address 192.168.1.5-192.168.1.36 inside
dhcpd enable inside
!threat-detection basic-threat
threat-detection scanning-threat shun duration 899
threat-detection statistics port
threat-detection statistics protocol
threat-detection statistics access-list
threat-detection statistics tcp-intercept rate-interval 30 burst-rate 400 average-rate 200
webvpn
!
class-map inspection_default
match default-inspection-traffic
!
!
policy-map type inspect dns preset_dns_map
parameters
message-length maximum 512
policy-map global_policy
class inspection_default
inspect dns preset_dns_map
inspect ftp
inspect h323 h225
inspect h323 ras
inspect rsh
inspect rtsp
inspect esmtp
inspect sqlnet
inspect skinny
inspect sunrpc
inspect xdmcp
inspect sip
inspect netbios
inspect tftp
!
service-policy global_policy global
prompt hostname context
Cryptochecksum:
: endAny suggestion how i can make it work</description> <content:encoded><![CDATA[<p>Hi thank for the wonderful info. I have a small scenario im trying in my pc.<br
/> I have an asa 5505 with inside interface 192.168.1.0/24 and outside 192.168.0.0/24<br
/> The inside interface pc&#8217;s are assigned dhcp ip addresses from the asa. On one of the inside pc&#8217;s i have a vmware workstation in the network 10.10.10.0/24<br
/> i have done everything u mentioned here but the vmware workstation does not connect to the internet.<br
/> ASA Version 8.2(1)<br
/> !<br
/> hostname ciscoasa<br
/> enable password  encrypted<br
/> passwd  encrypted<br
/> names<br
/> !<br
/> interface Vlan1<br
/> mac-address xxxx.xxxx.xxxx<br
/> nameif inside<br
/> security-level 100<br
/> ip address 192.168.1.1 255.255.255.0<br
/> !<br
/> interface Vlan2<br
/> nameif outside<br
/> security-level 0<br
/> ip address 192.168.0.10 255.255.255.0<br
/> !<br
/> interface Ethernet0/0<br
/> switchport access vlan 2<br
/> !<br
/> interface Ethernet0/1<br
/> !<br
/> interface Ethernet0/2<br
/> speed auto<br
/> duplex auto<br
/> !<br
/> interface Ethernet0/3<br
/> !<br
/> interface Ethernet0/4<br
/> speed auto<br
/> duplex auto<br
/> !<br
/> interface Ethernet0/5<br
/> !<br
/> interface Ethernet0/6<br
/> !<br
/> interface Ethernet0/7<br
/> !<br
/> ftp mode passive<br
/> same-security-traffic permit inter-interface<br
/> same-security-traffic permit intra-interface<br
/> access-list access_inbound extended permit tcp any host 192.168.1.0 eq www<br
/> access-list access_inbound extended permit tcp any host 10.10.10.0 eq www<br
/> pager lines 24<br
/> logging enable<br
/> logging timestamp<br
/> logging asdm informational<br
/> mtu inside 1500<br
/> mtu outside 1500<br
/> icmp unreachable rate-limit 1 burst-size 1<br
/> icmp deny any outside<br
/> asdm history enable<br
/> arp inside 10.10.10.10 503d.e553.8cdb alias<br
/> arp timeout 14400<br
/> global (outside) 1 interface<br
/> nat (inside) 1 10.10.10.0 255.255.255.0<br
/> nat (inside) 1 192.168.1.0 255.255.255.0<br
/> nat (inside) 1 0.0.0.0 0.0.0.0<br
/> access-group access_inbound in interface outside<br
/> route outside 0.0.0.0 0.0.0.0 192.168.0.1 1<br
/> route inside 10.10.10.0 255.255.255.0 192.168.1.1 1<br
/> timeout xlate 3:00:00<br
/> timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02<br
/> timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00<br
/> timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00<br
/> timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute<br
/> timeout tcp-proxy-reassembly 0:01:00<br
/> dynamic-access-policy-record DfltAccessPolicy<br
/> http server enable<br
/> http 192.168.1.0 255.255.255.0 inside<br
/> no snmp-server location<br
/> no snmp-server contact<br
/> snmp-server enable traps snmp authentication linkup linkdown coldstart<br
/> crypto ipsec security-association lifetime seconds 28800<br
/> crypto ipsec security-association lifetime kilobytes 4608000<br
/> telnet timeout 5<br
/> ssh timeout 5<br
/> console timeout 0<br
/> management-access inside<br
/> dhcpd auto_config outside<br
/> !<br
/> dhcpd address 192.168.1.5-192.168.1.36 inside<br
/> dhcpd enable inside<br
/> !</p><p>threat-detection basic-threat<br
/> threat-detection scanning-threat shun duration 899<br
/> threat-detection statistics port<br
/> threat-detection statistics protocol<br
/> threat-detection statistics access-list<br
/> threat-detection statistics tcp-intercept rate-interval 30 burst-rate 400 average-rate 200<br
/> webvpn<br
/> !<br
/> class-map inspection_default<br
/> match default-inspection-traffic<br
/> !<br
/> !<br
/> policy-map type inspect dns preset_dns_map<br
/> parameters<br
/> message-length maximum 512<br
/> policy-map global_policy<br
/> class inspection_default<br
/> inspect dns preset_dns_map<br
/> inspect ftp<br
/> inspect h323 h225<br
/> inspect h323 ras<br
/> inspect rsh<br
/> inspect rtsp<br
/> inspect esmtp<br
/> inspect sqlnet<br
/> inspect skinny<br
/> inspect sunrpc<br
/> inspect xdmcp<br
/> inspect sip<br
/> inspect netbios<br
/> inspect tftp<br
/> !<br
/> service-policy global_policy global<br
/> prompt hostname context<br
/> Cryptochecksum:<br
/> : end</p><p>Any suggestion how i can make it work</p> ]]></content:encoded> </item> </channel> </rss>
<!-- Served from: www.ducea.com @ 2012-02-08 19:57:01 by W3 Total Cache -->
