4-13
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 4 Configuring Switch Ports and VLAN Interfaces for the Cisco ASA 5505 Adaptive Security Appliance
Allowing Communication Between VLAN Interfaces on the Same Security Level
hostname(config-if)#
security-level 50
hostname(config-if)#
ip address 10.1.2.1 255.255.255.0
hostname(config-if)#
no shutdown
hostname(config-if)#
failover lan faillink vlan500
hostname(config)#
failover interface ip faillink 10.4.1.1 255.255.255.0 standby 10.4.1.2
255.255.255.0
hostname(config)#
interface ethernet 0/0
hostname(config-if)#
switchport access vlan 100
hostname(config-if)#
no shutdown
hostname(config-if)#
interface ethernet 0/1
hostname(config-if)#
switchport mode trunk
hostname(config-if)#
switchport trunk allowed vlan 200-202
hostname(config-if)#
no shutdown
hostname(config-if)#
interface ethernet 0/2
hostname(config-if)#
switchport access vlan 300
hostname(config-if)#
no shutdown
hostname(config-if)#
interface ethernet 0/3
hostname(config-if)#
switchport access vlan 400
hostname(config-if)#
no shutdown
hostname(config-if)#
interface ethernet 0/4
hostname(config-if)#
switchport access vlan 500
hostname(config-if)#
no shutdown
Allowing Communication Between VLAN Interfaces on the
Same Security Level
By default, interfaces on the same security level cannot communicate with each other. Allowing
communication between same security interfaces lets traffic flow freely between all same security
interfaces without access lists.
Note
If you enable NAT control, you do not need to configure NAT between same security level interfaces.
See the
“NAT and Same Security Level Interfaces” section on page 17-13
for more information on NAT
and same security level interfaces.
If you enable same security interface communication, you can still configure interfaces at different
security levels as usual.
To enable interfaces on the same security level so that they can communicate with each other, enter the
following command:
hostname(config)#
same-security-traffic permit inter-interface
To disable this setting, use the
no
form of this command.
Содержание 500 Series
Страница 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Страница 45: ...P A R T 1 Getting Started and General Information ...
Страница 46: ......
Страница 277: ...P A R T 2 Configuring the Firewall ...
Страница 278: ......
Страница 354: ...17 38 Cisco Security Appliance Command Line Configuration Guide OL 12172 03 Chapter 17 Configuring NAT NAT Examples ...
Страница 561: ...P A R T 3 Configuring VPN ...
Страница 562: ......
Страница 891: ...P A R T 4 System Administration ...
Страница 892: ......
Страница 975: ...P A R T 5 Reference ...
Страница 976: ......