4-6
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 4 Configuring Switch Ports and VLAN Interfaces for the Cisco ASA 5505 Adaptive Security Appliance
Configuring VLAN Interfaces
Note
If you are using failover, do not use this procedure to name interfaces that you are reserving for failover
communications. See
Chapter 14, “Configuring Failover,”
to configure the failover link.
If you change the security level of an interface, and you do not want to wait for existing connections to
time out before the new security information is used, you can clear the connections using the
clear local-host
command.
To configure a VLAN interface, perform the following steps:
Step 1
To specify the VLAN ID, enter the following command:
hostname(config)#
interface
vlan
number
Where the
number
is between 1 and 4090.
For example, enter the following command:
hostname(config)#
interface
vlan 100
To remove this VLAN interface and all associated configuration, enter the
no interface vlan
command.
Because this interface also includes the interface name configuration, and the name is used in other
commands, those commands are also removed.
Step 2
(Optional) For the Base license, allow this interface to be the third VLAN by limiting it from initiating
contact to one other VLAN using the following command:
hostname(config-if)#
no forward interface vlan
number
Where
number
specifies the VLAN ID to which this VLAN interface cannot initiate traffic.
With the Base license, you can only configure a third VLAN if you use this command to limit it.
For example, you have one VLAN assigned to the outside for Internet access, one VLAN assigned to an
inside business network, and a third VLAN assigned to your home network. The home network does not
need to access the business network, so you can use the
no forward interface
command on the home
VLAN; the business network can access the home network, but the home network cannot access the
business network.
If you already have two VLAN interfaces configured with a
nameif
command, be sure to enter the
no
forward interface
command before the
nameif
command on the third interface; the adaptive security
appliance does not allow three fully functioning VLAN interfaces with the Base license on the ASA 5505
adaptive security appliance.
Note
If you upgrade to the Security Plus license, you can remove this command and achieve full
functionality for this interface. If you leave this command in place, this interface continues to be
limited even after upgrading.
Step 3
To name the interface, enter the following command:
hostname(config-if)#
nameif
name
The
name
is a text
string up to 48 characters, and is not case-sensitive. You can change the name by
reentering this command with a new value. Do not enter the
no
form, because that command causes all
commands that refer to that name to be deleted.
Step 4
To set the security level, enter the following command:
hostname(config-if)#
security-level
number
Содержание 500 Series
Страница 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Страница 45: ...P A R T 1 Getting Started and General Information ...
Страница 46: ......
Страница 277: ...P A R T 2 Configuring the Firewall ...
Страница 278: ......
Страница 354: ...17 38 Cisco Security Appliance Command Line Configuration Guide OL 12172 03 Chapter 17 Configuring NAT NAT Examples ...
Страница 561: ...P A R T 3 Configuring VPN ...
Страница 562: ......
Страница 891: ...P A R T 4 System Administration ...
Страница 892: ......
Страница 975: ...P A R T 5 Reference ...
Страница 976: ......