1-7
Cisco ASA Series CLI Configuration Guide
Chapter 1 Starting Interface Configuration (ASA 5505)
Starting ASA 5505 Interface Configuration
Detailed Steps
What to Do Next
Configure the switch ports. See the
“Configuring and Enabling Switch Ports as Access Ports” section on
“Configuring and Enabling Switch Ports as Trunk Ports” section on page 1-9
.
Configuring and Enabling Switch Ports as Access Ports
By default (with no configuration), all switch ports are shut down, and assigned to VLAN 1. To assign
a switch port to a single VLAN, configure it as an access port. To create a trunk port to carry multiple
VLANs, see the
“Configuring and Enabling Switch Ports as Trunk Ports” section on page 1-9
. If you
have a factory default configuration, see the
“ASA 5505 Default Configuration” section on page 1-19
check if you want to change the default interface settings according to this procedure.
For more information about ASA 5505 interfaces, see the
“Information About ASA 5505 Interfaces”
Command
Purpose
Step 1
interface
vlan
number
Example:
hostname(config)# interface vlan 100
Adds a VLAN interface, where the
number
is between 1 and 4090.
To remove this VLAN interface and all associated configuration,
enter the
no interface vlan
command. Because this interface also
includes the interface name configuration, and the name is used in
other commands, those commands are also removed.
Step 2
(Optional for the Base license)
no forward interface vlan
number
Example:
hostname(config-if)# no forward interface
vlan 101
Allows this interface to be the third VLAN by limiting it from
initiating contact to one other VLAN.
The
number
specifies the VLAN ID to which this VLAN interface
cannot initiate traffic.
With the Base license, you can only configure a third VLAN if
you use this command to limit it.
For example, you have one VLAN assigned to the outside for
Internet access, one VLAN assigned to an inside business
network, and a third VLAN assigned to your home network. The
home network does not need to access the business network, so
you can use the
no forward interface
command on the home
VLAN; the business network can access the home network, but
the home network cannot access the business network.
If you already have two VLAN interfaces configured with a
nameif
command, be sure to enter the
no forward interface
command before the
nameif
command on the third interface; the
ASA does not allow three fully functioning VLAN interfaces with
the Base license on the ASA 5505.
Note
If you upgrade to the Security Plus license, you can
remove this command and achieve full functionality for
this interface. If you leave this command in place, this
interface continues to be limited even after upgrading.
Summary of Contents for 5505 - ASA Firewall Edition Bundle
Page 28: ...Glossary GL 24 Cisco ASA Series CLI Configuration Guide ...
Page 61: ...P A R T 1 Getting Started with the ASA ...
Page 62: ......
Page 219: ...P A R T 2 Configuring High Availability and Scalability ...
Page 220: ......
Page 403: ...P A R T 2 Configuring Interfaces ...
Page 404: ......
Page 499: ...P A R T 2 Configuring Basic Settings ...
Page 500: ......
Page 533: ...P A R T 2 Configuring Objects and Access Lists ...
Page 534: ......
Page 601: ...P A R T 2 Configuring IP Routing ...
Page 602: ......
Page 745: ...P A R T 2 Configuring Network Address Translation ...
Page 746: ......
Page 845: ...P A R T 2 Configuring AAA Servers and the Local Database ...
Page 846: ......
Page 981: ...P A R T 2 Configuring Access Control ...
Page 982: ......
Page 1061: ...P A R T 2 Configuring Service Policies Using the Modular Policy Framework ...
Page 1062: ......
Page 1093: ...P A R T 2 Configuring Application Inspection ...
Page 1094: ......
Page 1191: ...P A R T 2 Configuring Unified Communications ...
Page 1192: ......
Page 1333: ...P A R T 2 Configuring Connection Settings and QoS ...
Page 1334: ......
Page 1379: ...P A R T 2 Configuring Advanced Network Protection ...
Page 1380: ......
Page 1475: ...P A R T 2 Configuring Modules ...
Page 1476: ......
Page 1549: ...P A R T 2 Configuring VPN ...
Page 1550: ......
Page 1965: ...P A R T 2 Configuring Logging SNMP and Smart Call Home ...
Page 1966: ......
Page 2059: ...P A R T 2 System Administration ...
Page 2060: ......
Page 2098: ...1 8 Cisco ASA Series CLI Configuration Guide Chapter 1 Troubleshooting Viewing the Coredump ...
Page 2099: ...P A R T 2 Reference ...
Page 2100: ......